โ˜๏ธ๐ŸŽฏ

AWS Cloud Practitioner
CLF-C02 in bite-size pieces

One idea per slide ยท memory hooks ยท exam traps ยท quizzes

โŒจ๏ธ โ†’/Space next ยท โ† back ยท M menu ยท N next quiz ยท F full screen ยท swipe on phone

Know your enemyThe exam at a glance

๐Ÿ“

65 questions

50 count. 15 are unscored tests โ€” you can't tell which.

โฑ๏ธ

90 minutes

โ‰ˆ 80 sec per question. Plenty of time โ€” don't rush.

๐ŸŽฏ

700 / 1000

Scaled score. You pass on the total, not per domain.

๐Ÿ’ต

USD 100

Test centre or online proctored. Valid for 3 years.

โœ… Two question types

Multiple choice: 1 right of 4.
Multiple response: 2+ right of 5+ (the question tells you how many).

๐ŸŽฒ No penalty for guessing

A blank answer = wrong. Never leave a question empty. Flag it and come back.

Study where the points are4 domains, 4 colours

๐Ÿ› ๏ธ D3 Technology & Services
34%
๐Ÿ” D2 Security & Compliance
30%
โ˜๏ธ D1 Cloud Concepts
24%
๐Ÿ’ฐ D4 Billing, Pricing & Support
12%
D2 + D3 = 64% of your score. Security and "which service fits?" are the big wins.
The colour of the top progress bar tells you which domain you are in.

Your brain, your rulesHow to use this deck

๐Ÿ…

Sprints

Do one domain block (โ‰ˆ15โ€“20 slides), then take the ๐Ÿงƒ brain break slide seriously.

๐Ÿง 

Yellow boxes

Memory hooks. Say them out loud. Silly = sticky.

๐Ÿชค

Red boxes

Exam traps โ€” the wrong answers AWS loves to offer.

โ“

Quizzes

Click an answer. You get the reason at once. Score is saved in your browser.

๐Ÿƒ

Flip cards

Recap slides. Guess first, then tap to flip.

๐Ÿ”

Repeat

Day 1 read. Day 2 quizzes only (press N). Day 3 the final mock + cheat sheet.

Exam techniqueThe 3-step answer method

1

Find the keyword

"least operational overhead", "most cost-effective", "audit", "DDoS", "serverless"โ€ฆ

2

Map keyword โ†’ service

Most questions are a lookup: "who made this API call?" โ†’ CloudTrail.

3

Kill the distractors

Remove made-up or wrong-category services first. Then pick the managed / simplest option.

When in doubt on CLF-C02, AWS usually wants the managed, serverless, pay-as-you-go answer.
Words like "least", "NOT", "MOST" flip the meaning. Read the last line of the question twice.
D1

Cloud Concepts

24% of your score

Why cloud ยท Well-Architected ยท Migration ยท Cloud economics

DefinitionWhat is cloud computing?

The on-demand delivery of IT resources over the internet with pay-as-you-go pricing.

๐Ÿ”Œ

Like electricity

You don't build a power plant. You plug in and pay for what you use.

โšก

On demand

Servers in minutes, not weeks of ordering hardware.

๐Ÿงพ

Pay as you go

Turn it off โ†’ stop paying. No big upfront purchase.

Classic exam listThe 6 advantages of cloud computing

๐Ÿ”

1 ยท Trade fixed expense for variable expense

No upfront data-centre spend. Pay only when you use.

๐Ÿญ

2 ยท Benefit from massive economies of scale

AWS buys huge volumes โ†’ lower prices for you.

๐Ÿ”ฎ

3 ยท Stop guessing capacity

Scale up or down with demand. No idle or overloaded servers.

๐Ÿš€

4 ยท Increase speed and agility

New resources in minutes โ†’ experiment fast, fail cheap.

๐Ÿงน

5 ยท Stop spending money running and maintaining data centres

Focus on customers, not racking and cooling servers.

๐ŸŒ

6 ยท Go global in minutes

Deploy in many Regions โ†’ low latency for users worldwide.

๐Ÿ’ธ Pay less (1, 2) ยท ๐Ÿ”ฎ Guess less (3) ยท ๐Ÿš€ Move faster (4) ยท ๐Ÿงน Drop the data centre (5) ยท ๐ŸŒ Go global (6)

Words the exam lovesCloud vocabulary

๐Ÿช—

Elasticity

Resources grow and shrink automatically to match demand. (Auto Scaling)

๐Ÿ“ˆ

Scalability

The system can handle more load by adding resources.

๐ŸŸข

High availability

Stays up with minimal downtime โ€” e.g. run in multiple AZs.

๐Ÿ›ก๏ธ

Fault tolerance

Keeps working even when a component fails (no user impact).

๐Ÿ‡

Agility

Speed to try new things: low cost + fast provisioning.

๐Ÿ’Ž

Durability

Data is not lost. S3 = 99.999999999% (11 nines).

Elasticity โ‰  scalability. Elasticity = automatic, both directions, follows demand. "Scale in when traffic drops to save money" โ†’ elasticity.

Picture itScale up vs scale out

โฌ†๏ธ Vertical (scale up) small BIGGER instance

Bigger machine (more CPU/RAM). Has a ceiling. Often needs a restart.

โžก๏ธ Horizontal (scale out) MORE instances

Add more machines behind a load balancer. The cloud-native way.

Scale up = grow taller (one bigger server). Scale out = add more friends (more servers). Shrinking back = scale down / scale in.

Cloud service models๐Ÿ• Pizza as a service

ModelPizza versionYou manageAWS example
๐Ÿ—๏ธ IaaS
Infrastructure
Buy dough + oven time, you cookOS, patches, apps, dataAmazon EC2, Amazon VPC
๐Ÿงฐ PaaS
Platform
Pizza delivered, you set the tableYour code + dataAWS Elastic Beanstalk
๐Ÿ“ฆ SaaS
Software
Eat at the restaurantJust use it (your data/settings)Webmail, Salesforce, Amazon Connect (contact centre)
The further down the table, the less you manage. IaaS = "I do a lot", SaaS = "So easy".

Where does it run?Cloud deployment models

โ˜๏ธ

Cloud (all-in)

Everything runs in the public cloud. New cloud-native apps or fully migrated.

๐ŸŒ‰

Hybrid

Connect on-premises + cloud. Keep some systems on-site (legacy, regulation). E.g. AWS Outposts, VPN, Direct Connect.

๐Ÿข

On-premises (private cloud)

Your own data centre with virtualisation / resource-management tools.

"Keep some apps in our data centre and run new ones on AWS, connected together" โ†’ Hybrid.

An online shop adds servers automatically during a holiday sale and removes them when traffic drops. Which cloud concept is this?

Automatic growth and shrinking to match demand = elasticity. Fault tolerance is about surviving failures; durability is about not losing data.

Which are advantages of cloud computing listed by AWS?

Correct: Stop guessing capacity and Go global in minutes. Option A is backwards โ€” you trade fixed for variable. Watch for reversed wording!

Cloud economicsOn-premises: you must guess

time โ†’ capacity / demand ๐Ÿ’ธ paid but idle ๐Ÿ’ธ idle ๐Ÿ˜ก not enough! ๐Ÿ˜ก not enough!

โ” On-prem capacity (big steps you buy upfront) ยท โ” Real demand ยท โ”… Cloud capacity (follows demand)

On-prem = CapEx (capital expense, upfront, fixed). Cloud = OpEx (operating expense, variable, pay as you go).

Total Cost of Ownership (TCO)The hidden costs of on-premises

๐Ÿ–ฅ๏ธ

Servers, storage, network gear

๐Ÿข

Building / rack space (real estate)

โšก

Power + cooling

๐Ÿ‘ท

Staff to install, patch, replace hardware

๐Ÿ”’

Physical security

๐Ÿ“œ

Software licences

๐Ÿ”„

Hardware refresh every few years

๐Ÿงฏ

Disaster recovery site

Cloud removes most of these. Economies of scale: AWS spreads these costs over millions of customers โ†’ lower prices.
Business-case tool for migration TCO: Migration Evaluator. Estimating new AWS costs: AWS Pricing Calculator.

Cloud economicsLicensing ยท Rightsizing ยท Automation

๐Ÿ“œ

Licensing

License included: price includes the licence (e.g. Windows on EC2, Oracle SE2 / SQL Server on RDS).

BYOL (Bring Your Own License): reuse licences you already own. Often needs Dedicated Hosts (per-socket / per-core licences).

Track licences: AWS License Manager.

๐Ÿ“

Rightsizing

Match instance type + size to the real workload. Stop paying for idle CPU.

Tools: AWS Compute Optimizer, Cost Explorer rightsizing recommendations, Trusted Advisor.

๐Ÿค–

Automation

Infrastructure as code (CloudFormation), Auto Scaling, scheduled start/stop.

Benefits: fewer human errors, repeatable, faster, cheaper.

Rightsizing = buying the right shoe size. Too big wastes money, too small hurts.

A company wants to move servers to AWS and reuse its existing Windows Server licences that are tied to physical cores. What should it use?

Socket/core-bound BYOL licences โ†’ Dedicated Hosts (you see the physical server's sockets and cores). License-included means paying AWS for a new licence.

Which statement BEST describes the change in cost model when moving to AWS?

Cloud swaps CapEx (upfront, fixed) for OpEx (variable, pay-as-you-go). Option A is the reverse.

AWS Well-Architected FrameworkThe 6 pillars ๐Ÿ›๏ธ

WELL-ARCHITECTED OperationalExcellence Security Reliability PerformanceEfficiency CostOptimization Sustainability Review your workloads for free with the AWS Well-Architected Tool
"CROPS + S" โ†’ Cost ยท Reliability ยท Operational excellence ยท Performance efficiency ยท Security ยท + Sustainability (the newest, added 2021).

Tell them apartKeyword โ†’ pillar

PillarBig ideaExam keywords
โš™๏ธ Operational excellenceRun and improve operationsoperations as code (IaC), small reversible changes, learn from failures, observability
๐Ÿ” SecurityProtect data and systemsleast privilege, traceability, encrypt, security at all layers, prepare for incidents
๐Ÿงฑ ReliabilityWork correctly + recoverrecover from failure automatically, Multi-AZ, test recovery, stop guessing capacity
๐ŸŽ๏ธ Performance efficiencyUse resources efficientlyright instance type, serverless, go global in minutes, experiment more often
๐Ÿ’ฐ Cost optimizationAvoid unnecessary costpay only for what you use, measure efficiency, cloud financial management, rightsizing
๐ŸŒฑ SustainabilityReduce environmental impactmaximise utilisation, managed services, reduce energy and waste, shared responsibility for sustainability
"Recover from failure" โ†’ Reliability (not performance). "Choose the right resource type for the job" โ†’ Performance efficiency.

Which Well-Architected pillar focuses on a workload's ability to recover automatically from infrastructure or service failures?

Reliability = work correctly and consistently, and recover from failure.

A team performs operations as code and makes frequent, small, reversible changes. Which pillar does this design principle belong to?

"Perform operations as code" and "make frequent, small, reversible changes" are Operational excellence design principles.

AWS CAFCloud Adoption Framework = the migration "playbook"

๐Ÿ‘” Business-side perspectives

Business strategy โ†’ business outcomes

People culture, skills, change

Governance programs, benefits, risk

๐Ÿ› ๏ธ Technical-side perspectives

Platform build the cloud platform

Security confidentiality, integrity, availability

Operations run and support services

๐ŸŽฏ Business outcomes

Reduced business risk ยท Improved ESG performance ยท Increased revenue ยท Increased operational efficiency

๐Ÿ”„ Transformation phases

Envision โ†’ Align โ†’ Launch โ†’ Scale

Perspectives: "Big People Govern, Platforms Secure Operations". Phases: "Every Astronaut Lands Safely".

Migration strategiesThe 7 Rs โ€” from lazy to heavy

little effort / little cloud benefit most effort / most cloud benefit
RMeaningNickname / example
๐Ÿ—‘๏ธ RetireTurn it off โ€” not needed"Delete it"
โธ๏ธ RetainKeep on-prem for now"Not yet" (revisit later)
๐Ÿšš RehostMove as-is to EC2Lift and shift ยท AWS Application Migration Service
๐Ÿ“ฆ RelocateMove at hypervisor level, no app changee.g. move VMware VMs to VMware Cloud on AWS / Amazon EVS
๐Ÿ”ง ReplatformSmall optimisation, same coreLift, tinker and shift ยท self-managed DB โ†’ Amazon RDS
๐Ÿ›’ RepurchaseSwitch to a different productDrop and shop ยท move to SaaS
๐Ÿ—๏ธ RefactorRe-architect for cloud-nativee.g. monolith โ†’ serverless/microservices

Resources for the migration journeyMigration tools

Discover what servers + dependencies you have on-prem
โ†’
AWS Application Discovery Service
Build a business case / projected AWS cost
โ†’
Migration Evaluator
Track all migrations in one place
โ†’
AWS Migration Hub
Lift-and-shift servers (rehost) to AWS
โ†’
AWS Application Migration Service
Move a database (source stays online, continuous replication)
โ†’
AWS DMS (Database Migration Service)
Convert schema between different DB engines (e.g. Oracle โ†’ Aurora PostgreSQL)
โ†’
AWS SCT (Schema Conversion Tool)
Fast recovery of servers into AWS after a disaster
โ†’
AWS Elastic Disaster Recovery
The exam still uses these names. In real life, Migration Hub and Application Discovery Service closed to new customers on 7 Nov 2025 โ€” AWS Transform replaces them.
Older study notes mention the AWS Snow Family (Snowcone, Snowball, Snowmobile). It is not on the current CLF-C02 in-scope list, and Snow devices are no longer offered to new customers. Know only: "Snowball = physical device to ship lots of data offline".

A company moves its self-managed MySQL database from an on-premises server to Amazon RDS for MySQL, without changing the application code. Which migration strategy is this?

Same engine, but now a managed platform โ†’ small optimisation = Replatform ("lift, tinker and shift"). Rehost would be copying the server as-is to EC2.

Which AWS CAF perspective focuses on culture, organisational change and building cloud skills (training)?

People = culture, workforce transformation, skills. Governance = programs, risk, benefits.

A company wants to migrate an on-premises Oracle database to Amazon Aurora PostgreSQL with minimal downtime. Which AWS services should it use?

Different engines (heterogeneous) โ†’ SCT converts the schema, DMS moves and continuously replicates the data while the source stays online.

Recap ยท guess, then tapDomain 1 flash cards

CapEx = upfront, fixed (on-prem). OpEx = variable, pay-as-you-go (cloud).
Cost, Reliability, Operational excellence, Performance efficiency, Security, Sustainability
Automatically add AND remove resources to match demand.
Rehost
Repurchase (move to a SaaS product)
Envision โ†’ Align โ†’ Launch โ†’ Scale
AWS SCT (schema) + AWS DMS (data)
EC2 Dedicated Hosts
๐Ÿงƒ๐Ÿšถ

Brain break โ€” 5 minutes

Stand up. Drink water. Say the 6 pillars out loud once: CROPS + S.

Next: Domain 2 โ€” Security (the 30% chunk) ๐Ÿ”

D2

Security & Compliance

30% of your score

Shared responsibility ยท IAM ยท Encryption ยท Security services ยท Logging ยท Compliance

#1 most tested ideaShared responsibility model

๐Ÿ‘ค CUSTOMER โ€” security IN the cloud Customer data IAM (users, permissions) ยท Applications ยท Guest OS patching ยท Firewall config (security groups) Encryption choices (client-side, server-side) ยท Network traffic protection โ˜๏ธ AWS โ€” security OF the cloud Software: compute ยท storage ยท database ยท networking (incl. the virtualisation layer) Hardware + global infrastructure: Regions ยท AZs ยท edge locations ยท physical data centre security
๐Ÿ  AWS builds and guards the house (OF). You lock your doors and protect your stuff inside (IN).

The more managed, the less you doWho patches what?

Layer๐Ÿ–ฅ๏ธ EC2 (IaaS)๐Ÿ—„๏ธ RDS (managed)ฮป Lambda (serverless)
Your data + access (IAM)YouYouYou
Application / codeYouYou (schemas, queries)You (function code)
Firewall rules (security groups)YouYouAWS*
Database engine / runtime patchesYouAWSAWS
Operating system patchesYou (guest OS)AWSAWS
Hardware, virtualisation, facilitiesAWSAWSAWS

* Lambda: no servers for you to firewall. If you attach a function to your VPC, you control its security groups.

๐Ÿค Shared controls (both sides)

Patch management, configuration management, awareness & training โ€” AWS does its part, you do yours.

๐Ÿ“ฅ Inherited controls

Physical and environmental controls โ€” you inherit them fully from AWS.

Under the shared responsibility model, which task is the customer's responsibility when using Amazon EC2?

On EC2 you own the guest OS and everything above it. Hypervisor, disks and facilities = AWS.

A company uses Amazon RDS. Which task does AWS perform for them?

RDS is managed: AWS patches the OS and DB engine (in your maintenance window). Users, security groups and data are still yours.

AWS Identity and Access Management (IAM)IAM in one picture

๐Ÿ‘ค Usera person / app, long-term creds ๐Ÿ‘ฅ Groupset of users (no nesting) ๐Ÿ“„ Policy (JSON)Allow / Deny ยท Action ยท Resource ๐ŸŽญ Roletemporary creds, assumed by users/services ๐Ÿ‘‘ Root userfull power โ€” lock it away

AWS managed policy

Ready-made by AWS (e.g. ReadOnlyAccess).

Customer managed policy

You write it โ€” reusable, tailored = best for least privilege.

Inline policy

Embedded in one user/group/role only.

Least privilege = give only the permissions needed, nothing more. Attach policies to groups, not individual users. An explicit Deny always wins.

๐Ÿ‘‘ The root userProtect it. Then don't use it.

โœ… Protect root

  • Turn on MFA
  • Strong, unique password
  • No root access keys (delete any)
  • Create an admin in IAM Identity Center for daily work
  • In AWS Organizations: centrally remove member-account root credentials

๐Ÿ‘‘ Tasks only root can do

  • Change root email / root password / root access keys
  • Close the account (standalone account)
  • Restore IAM permissions when the only admin locked themselves out
  • Activate IAM access to the Billing console
  • View certain tax invoices
  • Register as a seller in the Reserved Instance Marketplace
  • Enable MFA Delete on an S3 bucket
  • Fix an S3 bucket / SQS policy that denies everyone
  • Sign up for AWS GovCloud (US)
Older notes say "change the support plan" is root-only. The current AWS list no longer includes it.

How identities sign inAuthentication options

๐Ÿ”‘

MFA

Something you know + something you have. Passkeys / FIDO security keys, authenticator apps, hardware TOTP tokens.

๐Ÿ”

Password policy

Set length, complexity, rotation and reuse rules for IAM users.

๐Ÿ—๏ธ

Access keys

Access key ID + secret for CLI / SDK / API. Never put them in code. Prefer roles.

๐ŸŽญ

IAM roles

Temporary credentials. For EC2 โ†’ S3 access, Lambda permissions, and cross-account access.

๐Ÿข

IAM Identity Center

Single sign-on (SSO) for your workforce across many AWS accounts and apps. Connects to your corporate directory.

๐Ÿค

Federation

Use an external identity provider (SAML 2.0 / OIDC, e.g. Microsoft Entra ID, Okta) instead of creating IAM users.

Employees sign in once to many AWS accounts
โ†’
IAM Identity Center
Sign-up / sign-in for your app's customers (web/mobile)
โ†’
Amazon Cognito
Managed Microsoft Active Directory in AWS
โ†’
AWS Directory Service

Credential storage & encryption keysWhere do secrets live?

๐Ÿคซ

AWS Secrets Manager

Stores DB passwords, API keys. Automatic rotation built in. Paid per secret.

๐Ÿ—‚๏ธ

Systems Manager Parameter Store

Config values + secrets (SecureString). Standard tier free. No built-in rotation.

๐Ÿ”‘

AWS KMS

Create and manage encryption keys. AWS-managed, multi-tenant HSMs. Integrated with S3, EBS, RDSโ€ฆ Logged in CloudTrail.

๐Ÿงฑ

AWS CloudHSM

Dedicated hardware security module (single-tenant). You fully control keys. For strict compliance.

๐Ÿ“œ AWS Certificate Manager (ACM)

Provision, manage and auto-renew SSL/TLS certificates (HTTPS). Public certificates for use with ACM-integrated services (ELB, CloudFront, API Gateway) are free.

"Rotate secrets automatically" โ†’ Secrets Manager. "Dedicated / single-tenant HSM" โ†’ CloudHSM. "Manage encryption keys" โ†’ KMS.

Benefit of cloud securityEncryption: 2 states of data

๐Ÿ’ปUser ๐Ÿ”’ IN TRANSIT โ€” TLS / HTTPS, VPN data moving over a network (ACM certificates) ๐Ÿ—„๏ธ ๐Ÿ” AT REST S3 / EBS / RDS + KMS keys

At rest

Data stored on disk. S3 encrypts all new objects by default (SSE-S3). EBS, RDS, DynamoDB support KMS encryption.

In transit

Data moving between client and AWS or between services. Use TLS (HTTPS), VPN.

Encryption is the customer's choice and configuration (shared model) โ€” AWS gives the tools (KMS, ACM).

An application running on an Amazon EC2 instance needs to read objects from an S3 bucket. What is the MOST secure way to give it access?

IAM roles give temporary, automatically rotated credentials โ€” no long-term keys in code.

Which are AWS best practices for the AWS account root user?

MFA and no root access keys. You can't attach IAM policies to the root user (in AWS Organizations, an SCP can restrict a member account's root user). Daily work โ†’ admin user via IAM Identity Center.

A company needs to store database credentials and rotate them automatically every 30 days. Which service meets this with the LEAST effort?

Secrets Manager = store + automatic rotation. KMS manages encryption keys, not app passwords.

Meet the guard teamSecurity services (memorise these!)

๐Ÿ›ก๏ธ

AWS Shield

DDoS protection. Standard: free, automatic for all. Advanced: paid, 24/7 Shield Response Team, DDoS cost protection.

๐Ÿงฑ

AWS WAF

Web Application Firewall (layer 7). Blocks SQL injection, cross-site scripting, bad IPs, bots. On CloudFront, ALB, API Gateway.

๐ŸŽ›๏ธ

AWS Firewall Manager

Manage WAF, Shield Advanced and security group rules centrally across all accounts in AWS Organizations.

๐Ÿ•

Amazon GuardDuty

Intelligent threat detection. ML analyses CloudTrail, VPC Flow Logs, DNS logs โ†’ finds malicious activity.

๐Ÿ”

Amazon Inspector

Automated vulnerability scanning (CVEs, unintended network exposure) of EC2, container images in ECR, Lambda.

๐Ÿ•ต๏ธ

Amazon Macie

Finds sensitive data (PII) in S3 using ML. E.g. credit card numbers, passport IDs.

๐Ÿ”Ž

Amazon Detective

Investigate the root cause of security findings. Builds graphs from logs.

๐Ÿ“Š

AWS Security Hub

Single dashboard: collects findings from GuardDuty, Inspector, Macieโ€ฆ, checks best practices / standards.

Name note: the best-practice / standards checks are now called "AWS Security Hub CSPM". "Security Hub" is now the unified product that correlates findings from CSPM, GuardDuty, Inspector and Macie. For the exam: Security Hub = the central place for security findings and posture checks.

Make them stick๐Ÿง  One-line hooks

๐Ÿ• GuardDuty
โ†’
a guard dog that barks at threats it sees in your logs
๐Ÿ” Inspector
โ†’
a building inspector checking for weaknesses (vulnerabilities)
๐Ÿ•ต๏ธ Macie
โ†’
"Ma-see your secrets" โ€” finds PII in S3
๐Ÿ”Ž Detective
โ†’
arrives after the crime โ€” investigates root cause
๐Ÿ›ก๏ธ Shield
โ†’
blocks the flood โ†’ DDoS
๐Ÿงฑ WAF
โ†’
Web attacks: SQL injection, XSS (layer 7)
๐Ÿ“Š Security Hub
โ†’
the hub where all findings meet
AWS Marketplace sells third-party security products (firewalls, antivirus, SIEM) that you can run on AWS.

A company wants to automatically discover and classify personally identifiable information (PII) stored in Amazon S3 buckets. Which service should it use?

PII in S3 โ†’ Macie. Inspector = vulnerabilities, GuardDuty = threats, Shield = DDoS.

Which service protects a web application from SQL injection and cross-site scripting attacks?

Application-layer (layer 7) web exploits โ†’ AWS WAF. Shield is for DDoS. Security groups filter by IP/port only.

A company needs to scan its EC2 instances and container images for software vulnerabilities continuously. Which service meets this need?

Software vulnerabilities (CVEs) on EC2 / ECR / Lambda โ†’ Amazon Inspector.

Where are the logs?The 3 governance twins (that people mix up)

๐Ÿ‘ฃ

AWS CloudTrail

WHO did WHAT, WHEN โ€” records API calls / account activity.

โ†’ auditing, "who deleted my bucket?"

๐Ÿ“ˆ

Amazon CloudWatch

HOW is it doing? โ€” metrics, logs, alarms, dashboards.

โ†’ monitoring, "CPU over 80% โ†’ alert"

๐Ÿ“ธ

AWS Config

WHAT changed in resource configuration over time + compliance rules.

โ†’ "is every bucket encrypted? what did this SG look like last week?"

๐Ÿ“‹ IAM access reports

Credential report (all users + status of passwords, keys, MFA) ยท Last accessed information (remove unused permissions).

๐ŸŒŠ VPC Flow Logs

Capture IP traffic info going to and from network interfaces in your VPC.

CloudTrail = footprints on a trail (who walked here). CloudWatch = a wristwatch / health tracker. Config = before-and-after photos.

ComplianceProve it & learn it

๐Ÿ“

AWS Artifact

Self-service portal for AWS compliance reports (SOC, PCI, ISO certifications) and agreements (e.g. BAA for HIPAA). "Auditor wants AWS's PCI report" โ†’ Artifact.

๐ŸŒ

Compliance varies

By industry (HIPAA health, PCI DSS payments) and geography (GDPR EU, data residency). Not every service is in scope for every program โ€” check "AWS Services in Scope by Compliance Program". You choose the Region where data lives.

๐Ÿ“š AWS Knowledge Center

Answers to common support questions.

๐Ÿ›๏ธ AWS Security Center

aws.amazon.com/security โ€” security info, bulletins, best practices.

โœ๏ธ AWS Security Blog

Latest security news, how-tos.

โœ”๏ธ Trusted Advisor

Security checks: open ports, root MFA, public buckets.

Abuse from AWS resources (spam, attacks, malware hosting)? Report it to the AWS Trust & Safety team (abuse report form). Penetration testing on many services is allowed without prior approval โ€” but DoS testing is prohibited (needs a separate approval process).

Govern many accountsOrganizations ยท Control Tower ยท more

๐ŸŒณ

AWS Organizations

Group accounts into OUs. Service control policies (SCPs) set max permissions for accounts. Consolidated billing.

๐Ÿ—ผ

AWS Control Tower

Set up a secure multi-account landing zone fast, with best-practice controls (guardrails).

๐Ÿ›๏ธ

AWS Service Catalog

Catalogue of pre-approved products (e.g. CloudFormation templates) users can launch.

๐Ÿ”—

AWS RAM

Resource Access Manager โ€” share resources (subnets, Transit Gateways) across accounts.

๐Ÿ“

Service Quotas

View and request increases of service limits.

๐Ÿงพ

AWS License Manager

Track and enforce software licence usage.

An SCP never grants permissions โ€” it only sets the maximum (a guardrail). IAM policies still have to allow the action.

A security auditor needs to know which IAM user terminated an EC2 instance yesterday. Which service provides this information?

"Who did what" (API calls) โ†’ CloudTrail.

A company's auditor requests AWS's SOC 2 and PCI DSS compliance reports. Where can the company download them?

AWS's own compliance reports and agreements โ†’ AWS Artifact.

A company wants to track configuration changes to its AWS resources over time and get alerted when a resource becomes non-compliant with internal rules. Which service should it use?

Configuration history + compliance rules โ†’ AWS Config.

A company wants to prevent ALL accounts in a specific organizational unit (OU) from using services outside an approved list. What should it use?

SCPs apply guardrails to all accounts in an OU โ€” even the root user of member accounts.

Recap ยท guess, then tapDomain 2 flash cards

OF = AWS (hardware, facilities, global infra). IN = you (data, IAM, OS on EC2, config).
AWS Shield (Standard free; Advanced paid + response team)
AWS WAF
Amazon GuardDuty
Amazon Macie
AWS CloudTrail
AWS Artifact
AWS IAM Identity Center
Amazon Cognito
AWS Secrets Manager
๐Ÿงƒ๐Ÿง˜

Brain break โ€” 5 minutes

Close your eyes. Picture the guard dog ๐Ÿ• (GuardDuty), the inspector ๐Ÿ” and Macie ๐Ÿ•ต๏ธ searching S3.

Next: Domain 3 โ€” Technology & Services (the biggest, 34%) ๐Ÿ› ๏ธ

D3

Cloud Technology & Services

34% of your score โ€” the biggest

Access ยท Global infra ยท Compute ยท Databases ยท Network ยท Storage ยท AI/ML ยท Analytics ยท Others

Deploying & operating4 ways to talk to AWS

๐Ÿ–ฑ๏ธ

Management Console

Web UI. Great for learning and one-time tasks. Not repeatable.

โŒจ๏ธ

AWS CLI

Commands in a terminal. Scriptable โ†’ repeatable.

๐Ÿง‘โ€๐Ÿ’ป

SDKs / APIs

Call AWS from application code (Python, Java, JSโ€ฆ). Everything in AWS is an API call.

๐Ÿ“œ

Infrastructure as Code

AWS CloudFormation templates (JSON/YAML) โ†’ whole environments, repeatable, version-controlled.

๐ŸŒฑ AWS Elastic Beanstalk

Upload your code โ†’ AWS handles capacity, load balancing, scaling, health monitoring. PaaS. You keep control of the resources.

๐Ÿงฐ AWS Systems Manager

Operations hub for EC2 / on-prem servers: patching, run commands at scale, Session Manager (no SSH keys), Parameter Store.

One-time click โ†’ Console. Same environment many times (dev / test / prod, many Regions) โ†’ CloudFormation.

AWS global infrastructureRegion โŠƒ Availability Zones โŠƒ data centres

๐ŸŒ REGION (e.g. eu-west-1, Ireland) AZ a๐Ÿข๐Ÿข1+ data centres AZ b๐Ÿขseparate power, network AZ c๐Ÿข๐Ÿขlow-latency links ๐Ÿ“ Edge locations many more than Regions,in big cities worldwide โ†’ CloudFront (CDN)โ†’ Route 53 (DNS)โ†’ Global Accelerator ๐Ÿ™๏ธ Local Zonescompute near a city ๐Ÿญ OutpostsAWS racks on YOUR site
Region = geographic area with multiple (usually 3+) isolated AZs. AZ = 1+ data centres with their own power, cooling, networking. AZs don't share single points of failure.

4 factorsHow to choose a Region

โš–๏ธ

1 ยท Compliance

Data must stay in a country (data sovereignty / residency laws). Often the #1 factor.

โšก

2 ยท Latency

Close to your users = faster.

๐Ÿงฉ

3 ยท Service availability

Not every service / feature is in every Region.

๐Ÿ’ฒ

4 ยท Pricing

Prices differ by Region.

"Can Llamas Ski Properly?" โ€” Compliance, Latency, Services, Pricing.
Data does not leave a Region unless you move or replicate it.

Design for failureMulti-AZ vs multi-Region

๐Ÿข๐Ÿข

Multiple AZs โ†’ High availability

Run instances in 2+ AZs behind a load balancer. If one AZ fails, others keep serving. Standard best practice.

๐ŸŒ๐ŸŒ

Multiple Regions โ†’ when you needโ€ฆ

  • Disaster recovery / business continuity (whole Region outage)
  • Low latency for users around the world
  • Data sovereignty (keep each country's data local)
Backup & restore Pilot light Warm standby Multi-site active/active cheapest, slowest recoverymost expensive, fastest recovery

Bonus: disaster-recovery strategies, from cheap/slow to expensive/fast.

๐Ÿš‘ AWS Elastic Disaster Recovery

Continuous block-level replication of servers (on-prem or cloud) into a low-cost staging area in AWS. Launch recovered servers in minutes (RPO seconds, RTO minutes).

๐Ÿ—ƒ๏ธ AWS Backup

Scheduled, point-in-time backups of AWS resources from one central place. Restore when needed โ€” slower recovery.

What is the BEST way to make an application highly available within a single AWS Region?

Multi-AZ = high availability. AZs are isolated from each other's failures. Edge locations are for caching/DNS, not running your app servers.

A European company must keep customer data inside the EU by law. Which factor MOST directly drives its Region choice?

Legal data-residency rules = compliance / data sovereignty. It beats price and latency.

A company wants to continuously replicate its on-premises servers to AWS so that it can launch them in AWS within minutes if its data centre fails. Which service meets this need?

Continuous replication + fast recovery of whole servers โ†’ Elastic Disaster Recovery. AWS Backup takes scheduled point-in-time backups; it does not keep servers ready to launch in minutes.

Amazon EC2 โ€” virtual serversPick the right instance family

FamilyLettersUse it forHook
โš–๏ธ General purposeM, TWeb servers, small DBs, balancedM = Main / Medium. T = Tiny, burstable
๐Ÿงฎ Compute optimizedCBatch processing, gaming servers, HPC, ML inference, high-performance webC = CPU / Compute
๐Ÿง  Memory optimizedR, XIn-memory DBs, big real-time dataR = RAM
๐ŸŽฎ Accelerated computingP, G, Inf, TrnML training, graphics, GPUsG = Graphics / GPU
๐Ÿ’ฝ Storage optimizedI, D, HHigh sequential read/write on local storage, data warehousing, OLTPI = IOPS
Key pieces of an instance: AMI (Amazon Machine Image = the template: OS + software), instance type (CPU/RAM), storage (EBS / instance store), security group.

Elasticity in actionAuto Scaling + Elastic Load Balancing

๐Ÿ‘ฅusers โš–๏ธ ELBspreads traffic Auto Scaling group: min 2 ยท desired 4 ยท max 8 ๐Ÿ–ฅ๏ธ๐Ÿ–ฅ๏ธ๐Ÿ–ฅ๏ธ๐Ÿ–ฅ๏ธ๐Ÿ–ฅ๏ธ๐Ÿ–ฅ๏ธ AZ aAZ b

Application LB (ALB)

Layer 7 โ€” HTTP/HTTPS, route by URL path / host.

Network LB (NLB)

Layer 4 โ€” TCP/UDP, ultra-high performance, static IPs.

Gateway LB (GWLB)

Deploy third-party virtual appliances (firewalls, inspection).

Auto Scaling = elasticity (add/remove instances). Load balancer = spread traffic + health checks + single entry point.

Containers & serverlessWho runs the servers?

๐Ÿณ

Amazon ECS

AWS's own container orchestrator. Simple, deeply integrated.

โ˜ธ๏ธ

Amazon EKS

Managed Kubernetes. Pick when you already use Kubernetes / want portability.

๐Ÿ“ฆ

Amazon ECR

Container image registry (store Docker images).

๐Ÿšซ๐Ÿ–ฅ๏ธ

AWS Fargate

Serverless compute for containers โ€” run ECS/EKS tasks without managing EC2 instances.

ฮป

AWS Lambda

Run functions on events. No servers. Pay per request + duration (ms). Max 15 min per run.

๐Ÿงฑ

Amazon EC2

Full control of the OS. You manage it.

Serverless = no servers to manage, scales automatically, pay for use. CLF-C02 serverless set: Lambda, Fargate (+ DynamoDB, S3, SQS, SNS, Athena, Glue, EventBridgeโ€ฆ).

Other computeThe "easy button" services

Simple website / VPS, fixed low monthly price, no AWS expertise
โ†’
Amazon Lightsail
Upload code, AWS handles deployment, scaling, monitoring
โ†’
AWS Elastic Beanstalk
Run thousands of batch jobs, AWS schedules them
โ†’
AWS Batch
Run AWS services on-premises (low latency / local data)
โ†’
AWS Outposts
Run code on events, no servers
โ†’
AWS Lambda
Run containers, no servers
โ†’
AWS Fargate

A company wants to run containers on Amazon ECS without provisioning or managing EC2 instances. Which service should it use?

Fargate = serverless compute engine for containers. ECR only stores images.

A developer needs to resize images each time they are uploaded to S3. Each job takes 5 seconds. Which is the MOST cost-effective option with no servers to manage?

Short, event-driven job โ†’ Lambda. You pay only for the milliseconds it runs.

A company runs a large in-memory database that needs a lot of RAM. Which EC2 instance family is MOST suitable?

Big RAM needs โ†’ Memory optimized (R / X). Hook: R = RAM.

AWS database servicesWhich database? (keyword โ†’ service)

๐Ÿ—„๏ธ Relational, SQL, managed (MySQL, PostgreSQL, MariaDB, Oracle, SQL Server, Db2)
โ†’
Amazon RDS
๐Ÿš€ Relational, cloud-native, MySQL/PostgreSQL-compatible, high performance, 6 copies across 3 AZs
โ†’
Amazon Aurora
๐Ÿ”‘ NoSQL key-value, serverless, single-digit-millisecond at any scale
โ†’
Amazon DynamoDB
โšก In-memory cache (Valkey, Redis OSS, Memcached), microsecond reads
โ†’
Amazon ElastiCache
๐Ÿ“„ Document DB, MongoDB-compatible
โ†’
Amazon DocumentDB
๐Ÿ•ธ๏ธ Graph DB (social networks, fraud rings, recommendations)
โ†’
Amazon Neptune
๐Ÿญ Data warehouse, analytics (OLAP) over petabytes
โ†’
Amazon Redshift
๐Ÿšš Migrate a database to AWS (convert schema between engines)
โ†’
AWS DMS (+ AWS SCT)
DynamoDB = Don't need Boxes (serverless NoSQL). ElastiCache = cash in your pocket โ€” fast to grab. Neptune = network of relationships.

EC2-hosted vs AWS managedRun it yourself, or let AWS run it?

๐Ÿ”ง

Database on EC2

โœ… Full control (OS access, any engine/version, special settings)

โŒ You patch, back up, replicate, scale.

โ†’ choose when you need OS-level control or an unsupported engine.

๐Ÿค–

Managed (RDS, Aurora, DynamoDB)

โœ… AWS handles patching, backups, failover, scaling.

โŒ No OS access.

โ†’ choose for "least operational overhead".

RDS Multi-AZ

Standby copy in another AZ โ†’ automatic failover โ†’ high availability.

Read replicas

Copies that serve reads โ†’ read performance / scaling.

Multi-AZ = availability (disaster). Read replica = performance (scale reads). Don't swap them.

A gaming app needs a serverless NoSQL database with single-digit-millisecond latency at any scale. Which service fits?

Serverless + NoSQL key-value + ms latency โ†’ DynamoDB.

An application repeatedly reads the same data from its relational database, which slows it down. Which service can reduce database load by caching data in memory?

In-memory cache โ†’ ElastiCache.

A company needs to run complex analytical SQL queries across petabytes of historical sales data. Which service is designed for this?

Data warehouse / OLAP analytics โ†’ Redshift.

Amazon VPC โ€” your private networkVPC in one picture

๐ŸŒ Internet Internet GW VPC 10.0.0.0/16 (one Region) AZ a AZ b ๐ŸŸข Public subnetweb server ๐Ÿ–ฅ๏ธ ยท NAT gateway ๐Ÿ”route 0.0.0.0/0 โ†’ Internet GW ๐Ÿ”ด Private subnetdatabase ๐Ÿ—„๏ธ โ€” no direct internetoutbound updates via NAT gateway ๐ŸŸข Public subnetweb server ๐Ÿ–ฅ๏ธ ๐Ÿ”ด Private subnetdatabase standby ๐Ÿ—„๏ธ
Subnet

A range of IPs in one AZ.

Internet gateway

Lets a VPC talk to the internet.

NAT gateway

Private subnet โ†’ internet (outbound only).

Route table

Rules: where traffic goes.

Security in a VPCSecurity group vs network ACL

๐Ÿ›ก๏ธ Security group๐Ÿšง Network ACL
Works atInstance (network interface) levelSubnet level
StateStateful โ€” return traffic allowed automaticallyStateless โ€” must allow return traffic explicitly
RulesAllow rules onlyAllow and Deny rules (numbered, in order)
DefaultNew SG: no inbound rules (all inbound denied), all outbound allowedDefault NACL allows all in/out
๐Ÿ›ก๏ธ Security group = Stateful, Sticks to the Server. ๐Ÿšง NACL = the subnet's border guard with No memory (stateless) โ€” and it can say Deny.
"Block one specific bad IP address for the whole subnet" โ†’ NACL (security groups can't deny). Scanning instances for network exposure โ†’ Amazon Inspector.

Network connectivityHow do I connect?

Office โ†” VPC, encrypted over the public internet, quick to set up
โ†’
AWS Site-to-Site VPN
The two ends of a Site-to-Site VPN
โ†’
Virtual private gateway (or Transit Gateway) on the AWS side + customer gateway on your side
Individual remote users / laptops โ†’ VPC
โ†’
AWS Client VPN
Dedicated private line, consistent performance, doesn't use the internet
โ†’
AWS Direct Connect
Hub to connect many VPCs + on-prem networks
โ†’
AWS Transit Gateway
Private access to a service/endpoint without the internet
โ†’
AWS PrivateLink
Create, publish and secure APIs (front door for Lambda)
โ†’
Amazon API Gateway
Direct Connect = private, but not encrypted by default and takes weeks to provision. Need encryption quickly โ†’ VPN (you can also run VPN over Direct Connect).

Edge servicesGet users to your app โ€” fast

๐Ÿงญ

Amazon Route 53

DNS (name โ†’ IP), domain registration, health checks, routing policies: simple, weighted, latency, failover, geolocationโ€ฆ

๐Ÿšš

Amazon CloudFront

CDN: caches content (images, video, websites, APIs) at edge locations close to users. Works with WAF and Shield.

๐ŸŽ๏ธ

AWS Global Accelerator

Sends traffic over the AWS global network with static anycast IPs. Good for TCP/UDP (non-HTTP) apps and fast regional failover. No caching.

Route 53 = the phone book / GPS. CloudFront = local copies in shops near you. Global Accelerator = an express lane on the AWS highway.
"Cache static content close to users" โ†’ CloudFront (not Global Accelerator). Route 53's name comes from DNS port 53.

Which statement about security groups is correct?

Security groups: stateful, instance level, allow-only. NACLs are stateless, subnet level, allow+deny. Configuring them is the customer's job.

A company needs a dedicated, private network connection from its data centre to AWS with consistent bandwidth that does not travel over the public internet. Which service should it use?

Dedicated + private + consistent, not the internet โ†’ Direct Connect. VPNs run over the internet.

A media company wants to reduce latency for users worldwide who download videos stored in an S3 bucket in one Region. Which service should it use?

Cache content at edge locations near users โ†’ CloudFront.

AWS storage servicesObject ยท Block ยท File

๐Ÿชฃ

Object โ€” Amazon S3

Files as objects in buckets, accessed by URL/API. Unlimited total storage; one object up to 50 TB (raised from 5 TB in Dec 2025 โ€” older notes say 5 TB). Backups, data lakes, static websites, media.

๐Ÿ’ฝ

Block โ€” EBS / instance store

A hard drive for EC2. OS boot volumes, databases.

๐Ÿ—‚๏ธ

File โ€” EFS / FSx

Shared folder that many servers mount at once.

๐ŸŒ‰ AWS Storage Gateway

Hybrid: on-prem apps use cloud storage with a local cache. Types: S3 File Gateway, Volume Gateway, Tape Gateway (replace physical backup tapes).

๐Ÿ—ƒ๏ธ AWS Backup

Central backup plans + policies for EBS, EC2, RDS, DynamoDB, EFS, FSx, S3โ€ฆ across accounts and Regions. Compliance-friendly.

Block vs fileEBS vs instance store vs EFS vs FSx

๐Ÿ’ฝ EBSโšก Instance store๐Ÿ—‚๏ธ EFS๐ŸชŸ FSx
TypeBlock (network drive)Block (physically attached)File (NFS)File (managed third-party file systems)
Survives stop?Yes (persistent)No โ€” data lost on stop/terminateYesYes
ScopeOne AZ; usually one instanceThat one instanceMany instances, many AZsMany instances
Best forBoot volumes, databasesTemporary data, caches, buffersLinux shared files, auto-growsWindows File Server (SMB), NetApp ONTAP, OpenZFS
EBS = USB drive plugged by network (keep it). Instance store = scratch paper (gone when you stop). EFS = shared Folder for Linux. FSx for Windows = "File Server x (any flavour)".
EBS snapshots are incremental, Region-level backups (stored in S3). Restore a volume in any AZ of the Region, or copy the snapshot to another Region.

Amazon S3 storage classes๐Ÿ”ฅ Hot โ†’ ๐ŸงŠ cold

ClassUse whenRetrievalMin. daysAZs
๐Ÿ”ฅ S3 StandardFrequent accessmsโ€”3+
๐Ÿค– S3 Intelligent-TieringUnknown / changing access โ€” auto moves data, no retrieval feesms (archive tiers optional)โ€”3+
๐ŸŒค๏ธ S3 Standard-IAInfrequent, needs fast accessms + retrieval fee303+
๐ŸŒฅ๏ธ S3 One Zone-IAInfrequent, re-creatable data (lost if the AZ is destroyed)ms + fee301
โ„๏ธ Glacier Instant RetrievalArchive read ~once a quarter, needs ms accessms903+
๐ŸงŠ Glacier Flexible RetrievalArchive, wait minutesโ€“hours is OK1โ€“5 min to 12 h903+
๐Ÿ”๏ธ Glacier Deep ArchiveCheapest. Keep 7โ€“10 years for complianceโ‰ค 12 h (bulk โ‰ค 48 h)1803+

Also: S3 Express One Zone โ€” single-AZ class for the fastest, single-digit-ms performance. All classes: 11 nines durability.

The colder the class โ†’ the cheaper to store, the slower and pricier to retrieve, the longer the minimum stay.

Automate the coolingS3 Lifecycle policies

๐Ÿ”ฅ Standardday 0 ๐ŸŒค๏ธ Standard-IAafter 30 days ๐ŸงŠ Glacier Flexibleafter 90 days ๐Ÿ—‘๏ธ Expireafter 7 years

โžก๏ธ Transition actions

Move objects to a cheaper class after N days.

๐Ÿ—‘๏ธ Expiration actions

Delete objects (or old versions) after N days.

Access pattern known โ†’ Lifecycle policy. Access pattern unknown โ†’ Intelligent-Tiering.
Other S3 features: versioning (recover deleted/overwritten objects), replication to another Region, static website hosting, Transfer Acceleration, Block Public Access (on by default).

A company must keep financial records for 10 years for compliance. The data is almost never read, and a 12-hour retrieval time is acceptable. Which storage class is the MOST cost-effective?

Long-term, rarely accessed, hours OK โ†’ Glacier Deep Archive (lowest storage cost).

A company stores data in S3 but cannot predict how often each object will be accessed. Which storage class optimises cost automatically?

Unknown / changing access โ†’ Intelligent-Tiering moves objects between tiers automatically.

Several Linux EC2 instances in different Availability Zones need to read and write the same files at the same time. Which service should be used?

Shared Linux file system across many instances and AZs โ†’ EFS. EBS is tied to one AZ.

A company wants on-premises applications to use Amazon S3 storage through a local file share with low-latency cached access, and to replace its physical backup tapes. Which service should it use?

Hybrid, cached access to cloud storage (File / Volume / Tape gateway) โ†’ Storage Gateway.
๐Ÿงƒ๐ŸŽต

Brain break โ€” 5 minutes

Put on one song. Then come back for AI/ML โ€” it's the fun part ๐Ÿค–

AI & machine learningAI services = superpowers via API

๐Ÿง‘โ€๐Ÿ”ฌ

Amazon SageMaker AI

Build, train and deploy your own ML models (for data scientists).

๐Ÿ’ฌ

Amazon Q

Generative AI assistant for business users (Q Business) and developers (Q Developer).

๐Ÿ‘๏ธ

Amazon Rekognition

Image + video analysis: faces, objects, text, unsafe content.

๐Ÿ“„

Amazon Textract

Extract text, handwriting, forms and tables from scanned documents.

๐Ÿง 

Amazon Comprehend

NLP: sentiment, key phrases, entities, language of text.

๐ŸŒ

Amazon Translate

Translate text between languages.

๐Ÿ“

Amazon Transcribe

Speech โ†’ text (call recordings, subtitles).

๐Ÿฆœ

Amazon Polly

Text โ†’ speech (lifelike voices).

๐Ÿค–

Amazon Lex

Chatbots / voice bots (same tech as Alexa).

Make them stick๐Ÿง  AI hooks

๐Ÿฆœ Polly the parrot
โ†’
talks: text โ†’ speech
๐Ÿ“ Transcribe
โ†’
a transcript: speech โ†’ text
๐Ÿค– Lex
โ†’
Lexicon of a chatbot โ€” talks back to you
๐Ÿ‘๏ธ Rekognition
โ†’
recognises faces and objects in pictures
๐Ÿ“„ Textract
โ†’
extracts text from documents (more than OCR: forms + tables)
๐Ÿง  Comprehend
โ†’
comprehends the meaning / feeling of text
๐Ÿง‘โ€๐Ÿ”ฌ SageMaker AI
โ†’
the maker of your own custom models
Bonus (not on the in-scope list): Amazon Bedrock = API access to foundation models (generative AI) from Amazon and others.

Analytics servicesThe data pipeline, left to right

๐ŸŒŠ INGESTKinesisreal-time streams ๐Ÿชฃ STORES3 data lake ๐Ÿ”ง TRANSFORMGlue ยท EMRETL ยท Spark/Hadoop ๐Ÿ”Ž QUERYAthena ยท Redshiftยท OpenSearch ๐Ÿ“Š VISUALISEQuick Sight
SQL queries directly on files in S3, serverless, pay per query
โ†’
Amazon Athena
Real-time streaming data (clickstreams, IoT, logs)
โ†’
Amazon Kinesis
Serverless ETL + Data Catalog (crawlers find schemas)
โ†’
AWS Glue
Big-data frameworks: Apache Spark, Hadoop
โ†’
Amazon EMR
Search + log analytics (Elasticsearch-compatible)
โ†’
Amazon OpenSearch Service
BI dashboards and reports
โ†’
Amazon Quick Sight

Name note: Amazon QuickSight is now written "Amazon Quick Sight" (part of Amazon Quick Suite). Same service.

A company wants to convert recorded customer-support calls into text and then detect whether each customer was happy or angry. Which combination of services should it use?

Speech โ†’ text = Transcribe. Sentiment of text = Comprehend.

An insurance company receives thousands of scanned claim forms. It needs to extract the fields and tables automatically. Which service should it use?

Text, forms, tables from documents โ†’ Textract.

A data analyst wants to run standard SQL queries on log files stored in Amazon S3 without loading them into a database or managing servers. Which service fits BEST?

SQL on S3, serverless โ†’ Athena.

Application integrationMessages, events, workflows

๐Ÿ“ฌ

Amazon SQS

Queue. Producers drop messages, consumers pull them later. Decouples components, buffers spikes.

๐Ÿ“ฃ

Amazon SNS

Pub/sub. One message pushed to many subscribers: email, SMS, Lambda, SQS (fan-out). Alerts & notifications.

๐ŸšŒ

Amazon EventBridge

Serverless event bus. Route events from AWS services, SaaS apps, your apps to targets by rules. Also schedules (cron).

๐Ÿชœ

AWS Step Functions

Visual workflows that orchestrate many steps / services (with retries, branches).

SQS = a Queue at the post office (wait your turn, pull). SNS = a Notification megaphone (push to everyone). EventBridge = a bridge that routes events.

Other in-scope categoriesKeyword โ†’ service

โ˜Ž๏ธ Cloud contact centre / call centre
โ†’
Amazon Connect
โœ‰๏ธ Send marketing / transactional email at scale
โ†’
Amazon SES
๐Ÿ–ฅ๏ธ Full virtual desktops (Windows / Linux) for employees
โ†’
Amazon WorkSpaces
๐ŸชŸ Stream a single desktop application to a browser
โ†’
Amazon AppStream 2.0
๐ŸŒ Secure browser access to internal websites / SaaS
โ†’
Amazon WorkSpaces Secure Browser
๐Ÿ“ฑ Build + host front-end web and mobile apps fast
โ†’
AWS Amplify
๐Ÿ“ก Connect and manage IoT devices
โ†’
AWS IoT Core
๐Ÿ—๏ธ Compile + test code (build server)
โ†’
AWS CodeBuild
๐Ÿ” Automate the CI/CD release pipeline
โ†’
AWS CodePipeline
๐Ÿž Trace requests, debug distributed apps / microservices
โ†’
AWS X-Ray

Name note: AppStream 2.0 is now also called "Amazon WorkSpaces Applications". Same service.

Management & governanceKeyword โ†’ service

Metrics, logs, alarms
โ†’
CloudWatch
API call history / audit
โ†’
CloudTrail
Config history + rules
โ†’
AWS Config
Best-practice checks (cost, security, limitsโ€ฆ)
โ†’
Trusted Advisor
AWS service events affecting you
โ†’
AWS Health Dashboard
Infra as code templates
โ†’
CloudFormation
Patch / manage fleets of servers
โ†’
Systems Manager
Right-size EC2, Lambda, EBS (ML recommendations)
โ†’
Compute Optimizer
Review against the 6 pillars
โ†’
Well-Architected Tool
Multi-account, central billing, SCPs
โ†’
Organizations
Multi-account landing zone + guardrails
โ†’
Control Tower
Approved IT product catalogue
โ†’
Service Catalog
See / raise service limits
โ†’
Service Quotas
Scale EC2, DynamoDB, ECSโ€ฆ automatically
โ†’
AWS Auto Scaling

A company needs to send an email and an SMS alert to the operations team whenever a CloudWatch alarm fires. Which service should deliver the notifications?

Push notifications to people (email + SMS) from alarms โ†’ SNS. SES is for bulk/marketing emails from apps.

An order system's front end sometimes sends orders faster than the back end can process them. Which service lets the components work independently and buffer the orders?

Buffer + decouple โ†’ message queue = SQS.

A company wants to give remote employees secure, persistent Windows desktops that run in AWS, accessible from their own laptops. Which service should it use?

Virtual desktops (DaaS) โ†’ WorkSpaces.

Developers want to find which microservice is causing slow response times in their distributed application. Which service helps?

Trace requests across services and find bottlenecks โ†’ X-Ray.

Recap ยท guess, then tapDomain 3 flash cards

Region = geographic area. AZ = isolated data centre group(s) inside it.
AWS Fargate
Amazon EKS
Amazon DynamoDB
Security group
AWS Direct Connect
Amazon CloudFront
S3 Glacier Deep Archive
Amazon EFS
Amazon Polly
Amazon Athena
Amazon SNS
๐Ÿงƒ๐Ÿƒ

Brain break โ€” 5 minutes

You finished the biggest domain! ๐ŸŽ‰ Walk around. Last stop: money ๐Ÿ’ฐ

D4

Billing, Pricing & Support

12% of your score

Pricing models ยท Data transfer ยท Cost tools ยท Organizations ยท Support plans ยท Help resources

How AWS charges3 pricing principles

๐Ÿงพ

Pay as you go

Pay for what you use. No long-term contract needed.

๐Ÿค

Save when you commit

1- or 3-year commitments (Savings Plans, Reserved Instances) = big discounts.

๐Ÿ“ฆ

Pay less by using more

Volume tiers (e.g. S3 per-GB price drops as you store more).

๐ŸŽ AWS Free Tier (accounts created since 15 July 2025)

Free plan: up to USD 200 in credits (100 at sign-up + up to 100 for trying services), valid 6 months. No charges unless you upgrade to the Paid plan.

Always Free offers (e.g. Lambda requests, DynamoDB storage) stay free within monthly limits. Some services also have short trials.

Older accounts / older study notes: "12 months free" tier. You may still see that wording.

Compute purchasing optionsHow much can I save? (vs On-Demand)

๐ŸŽฐ Spot Instances
up to 90%
๐Ÿ“… EC2 Instance Savings Plan
up to 72%
๐Ÿ“… Standard Reserved Instance
up to 72%
๐Ÿ”„ Compute Savings Plan
up to 66%
๐Ÿ”„ Convertible RI
up to 66%
๐Ÿงพ On-Demand
More commitment + less flexibility = bigger discount. Spot = biggest discount but AWS can take it back with a 2-minute warning.

Decision guideWhich purchase option?

Short-term, unpredictable, can't be interrupted, new app testing
โ†’
๐Ÿงพ On-Demand
Steady, predictable use for 1 or 3 years
โ†’
๐Ÿ“… Reserved Instances or Savings Plans
Commit to $/hour, flexible across instance family, Region, OS, and Lambda + Fargate
โ†’
๐Ÿ”„ Compute Savings Plan
Fault-tolerant, flexible, can be interrupted (batch, CI, big data, image rendering)
โ†’
๐ŸŽฐ Spot Instances
BYOL (per-socket/core), compliance needs a physical server you control
โ†’
๐Ÿ  Dedicated Hosts
Hardware not shared with other customers, but no host control
โ†’
๐Ÿšช Dedicated Instances
Guarantee capacity in a specific AZ, any duration, no term commitment
โ†’
๐ŸŽŸ๏ธ On-Demand Capacity Reservations
Spot = "spot sale at the market โ€” cheap, but the seller can take it back". Dedicated Host = you rent the whole house. Dedicated Instance = your own room, landlord controls the house.

Reserved InstancesRI flexibility & behaviour in Organizations

โณ Terms & payment

1 or 3 years.

All Upfront (biggest discount) ยท Partial Upfront ยท No Upfront.

๐Ÿงฑ Standard vs Convertible

Standard: bigger discount; can change AZ / size; can be sold on the RI Marketplace.

Convertible: exchange for another family, OS, tenancy; smaller discount; can't be sold.

๐ŸŒ Regional vs Zonal

Regional: discount applies in any AZ + instance size flexibility (same family, Linux, default tenancy). No capacity reservation.

Zonal: reserves capacity in one AZ.

๐ŸŒณ RIs in AWS Organizations

With consolidated billing, RI and Savings Plans discounts are shared across all accounts in the organization by default. The management account can turn sharing off for specific accounts.

AWS now recommends Savings Plans for most compute commitments โ€” simpler and more flexible than RIs. RIs still exist (also for RDS, Redshift, ElastiCache, OpenSearch).

A company runs nightly video-rendering jobs that can be stopped and restarted at any time without problems. Which EC2 option is MOST cost-effective?

Interruptible + flexible โ†’ Spot (up to 90% off).

A company has steady compute use across EC2, AWS Lambda and AWS Fargate and changes instance families often. Which option gives a discount with the MOST flexibility?

Compute Savings Plans cover EC2 (any family, Region, OS), Lambda and Fargate. EC2 Instance SP is locked to one family in one Region.

A company uses AWS Organizations with consolidated billing. Account A bought Reserved Instances it does not fully use. What happens by default?

Consolidated billing shares RI and Savings Plans discounts across accounts by default (sharing can be turned off).

Data transferData in is free. Data out costs.

๐ŸŒInternet Region A AZ 1๐Ÿ–ฅ๏ธ๐Ÿ–ฅ๏ธ AZ 2๐Ÿ–ฅ๏ธ Region B๐Ÿ–ฅ๏ธ IN: FREE โœ… OUT to internet: ๐Ÿ’ฒ same AZ, private IP: free across AZs: ๐Ÿ’ฒ (small) to anotherRegion: ๐Ÿ’ฒ
Inbound from the internet = free. Outbound to the internet = charged. Between Regions = charged. Between AZs = charged (small). Same AZ over private IP = free. AWS origin โ†’ CloudFront = free.

Storage options and tiersWhat do you pay for in storage?

๐Ÿชฃ

Amazon S3

  • GB stored per month (by storage class)
  • Requests (PUT, GETโ€ฆ)
  • Retrieval fees (IA, Glacier classes)
  • Data transfer out
  • Management features (e.g. Intelligent-Tiering monitoring fee, replication)
๐Ÿ’ฝ

Amazon EBS

  • GB provisioned per month โ€” even if empty!
  • Provisioned IOPS / throughput (some volume types)
  • Snapshots (GB stored in S3)
๐Ÿ—‚๏ธ

Amazon EFS

GB used per month (grows and shrinks). Infrequent Access / Archive classes are cheaper.

๐ŸงŠ

Archive classes

Cheapest per GB, but minimum storage duration charges + retrieval fees.

EBS = pay for what you provision. S3 / EFS = pay for what you store.

Billing, budget & cost managementBefore ยท during ยท after

1

๐Ÿงฎ Before: AWS Pricing Calculator

Estimate the cost of an architecture before you build it. Free web tool.

2

๐Ÿšจ During: AWS Budgets

Set a cost / usage / RI / Savings Plans budget โ†’ alert (email, SNS) when actual or forecasted spend crosses it. Budget actions can apply policies or stop resources.

3

๐Ÿ“Š After: AWS Cost Explorer

Visualise and analyse past costs and usage, filter by service / tag / account, forecast, get RI / Savings Plans recommendations.

4

๐Ÿ“‘ Deepest: Cost and Usage Report

The most detailed line-item billing data (by hour, resource, tag) delivered to S3. Analyse with Athena / Quick Sight.

๐Ÿท๏ธ Cost allocation tags

Key-value labels (e.g. Project=Alpha) to split costs. Two types: AWS-generated and user-defined. You must activate them in the Billing console before they appear in Cost Explorer / CUR.

๐Ÿ”” Bonus: Cost Anomaly Detection

Uses ML to spot unusual spend and alert you.

Current prices: each service's public pricing page; programmatic access โ†’ AWS Price List API.

Calculator = future ๐Ÿ”ฎ ยท Budgets = alarm clock โฐ ยท Cost Explorer = rear-view mirror ๐Ÿชž (+ forecast) ยท CUR = the full receipt ๐Ÿงพ

AWS OrganizationsOne family, one bill

๐Ÿ‘‘ Management accountpays the single bill ๐Ÿ“ OU: Production ๐Ÿ“ OU: Dev ๐Ÿ“ OU: Sandbox ๐Ÿง‘โ€๐Ÿ’ผ๐Ÿง‘โ€๐Ÿ’ผ๐Ÿง‘โ€๐Ÿ’ผ๐Ÿง‘โ€๐Ÿ’ผ๐Ÿง‘โ€๐Ÿ’ผ member accounts ยท SCPs can be attached to the root, OUs or accounts

๐Ÿงพ One bill

Consolidated billing โ€” free feature.

๐Ÿ“ฆ Volume discounts

Usage from all accounts is combined for tiered pricing.

๐Ÿค Shared discounts

RI + Savings Plans discounts shared across accounts.

๐Ÿ›‚ SCPs

Central guardrails on what accounts can do.

A company wants to receive an email alert when its forecasted monthly AWS spend will exceed USD 5,000. Which service should it use?

Alerts on actual or forecasted spend โ†’ AWS Budgets.

Before migrating, a company wants to estimate the monthly cost of a new architecture on AWS. Which tool should it use?

Estimate before you build โ†’ Pricing Calculator. Cost Explorer analyses costs you already have.

A company wants to see AWS costs per project and per department. Which actions should it take?

Tag resources, then activate the tags as cost allocation tags. Then filter by tag in Cost Explorer / CUR.

AWS Support plans (current line-up)Pick your helper ๐Ÿ†˜

๐Ÿ†“ Basic๐Ÿ’ผ Business Support+๐Ÿข Enterprise Support๐Ÿ‘‘ Unified Operations
PriceFree, every accountFrom USD 29/month (or % of usage)From USD 5,000/monthFrom USD 50,000/month
Technical supportNo tech cases โ€” account & billing help, docs, re:Post24/7 phone, chat, email with AWS engineers + AI-powered help24/7 + AI24/7 + AI
Critical-case responseโ€”< 30 min< 15 min< 5 min
Trusted AdvisorCore checks (service limits + some security)Full set + Trusted Advisor PriorityFull set + Trusted Advisor PriorityFull set + Trusted Advisor Priority
Technical Account Managerโ€”โ€”Designated TAMDesignated TAM + specialist & incident engineers
ExtrasAWS Health DashboardAWS Health, Well-Architected reviews, cost-optimisation guidanceTAM-led Well-Architected reviews, event planning (AWS Countdown), Security Incident Response, billing conciergeEverything in Enterprise + designated domain-specialist and incident-management engineers, < 5 min response
Climb the stairs: Basic (free, no engineers) โ†’ Business+ (cheapest 24/7 engineers) โ†’ Enterprise (your own TAM) โ†’ Unified Ops (a whole team, 5 min).

โš ๏ธ Don't get confusedOld plan names you may still see

๐Ÿ—“๏ธ Retiring 1 January 2027

  • Developer (business-hours email only)
  • Business (24/7 phone/chat, < 1 h production down)
  • Enterprise On-Ramp (pool of TAMs, < 30 min)

Still offered only in AWS GovCloud (US).

โœ… The current exam guide lists

  • Basic Support
  • AWS Business Support+
  • AWS Enterprise Support
  • AWS Unified Operations
Cheapest plan with 24/7 access to engineers by phone
โ†’
Business Support+ (old notes: "Business")
Designated Technical Account Manager (TAM)
โ†’
Enterprise Support (or Unified Operations)
Fastest critical response (5 min), dedicated team
โ†’
Unified Operations
Free billing / account questions
โ†’
Basic Support

Monitor & optimiseTrusted Advisor & AWS Health

โœ”๏ธ

AWS Trusted Advisor

Checks your account against best practices. 6 categories:

๐Ÿ’ฐ Cost optimization๐ŸŽ๏ธ Performance๐Ÿ” Security๐Ÿ›ก๏ธ Fault tolerance๐Ÿ“ Service limitsโš™๏ธ Operational excellence

Examples: idle EC2 / unattached EBS (cost), open port 22 to world (security), no Multi-AZ (fault tolerance), close to a quota (limits).

๐Ÿฉบ

AWS Health Dashboard

Service health: public status of all AWS services.

Your account health: personalised alerts โ€” events and scheduled maintenance that affect your resources.

AWS Health API: programmatic access (with a paid support plan) โ†’ automate responses.

Trusted Advisor categories: "Cats Prefer Safe, Friendly, Stable Owners" โ€” Cost, Performance, Security, Fault tolerance, Service limits, Operational excellence.

Technical resourcesWhere to get help

Community Q&A with AWS experts (replaced the old forums)
โ†’
AWS re:Post
Articles answering the most common support questions
โ†’
AWS Knowledge Center
Proven strategies, guides, patterns from AWS experts
โ†’
AWS Prescriptive Guidance
Deep technical papers / user guides
โ†’
AWS Whitepapers ยท AWS Documentation ยท AWS Blogs
Open and manage support cases (account & billing cases are free on every plan)
โ†’
AWS Support Center
Official price of each service
โ†’
Service pricing pages (aws.amazon.com/pricing)
View bills, invoices, payments, credits
โ†’
Billing and Cost Management console
AWS's own experts to help deliver a project (paid)
โ†’
AWS Professional Services
Help designing an architecture (via your account team)
โ†’
AWS Solutions Architects
Report abuse (spam, attacks) coming from AWS resources
โ†’
AWS Trust & Safety team

AWS Partner Network (APN)Partners & AWS Marketplace

๐Ÿ’ฟ

ISVs

Independent software vendors โ€” build and sell software that runs on / integrates with AWS (often via Marketplace).

๐Ÿง‘โ€๐Ÿ”ง

System integrators (SIs)

Consulting / services partners that design, build, migrate and manage workloads for customers.

๐ŸŽ

Partner benefits

Partner training & certification, partner events, partner volume discounts, funding and marketing support.

๐Ÿ›’

AWS Marketplace

A curated digital catalogue to find, buy and deploy third-party software, data and services. Charges appear on your AWS bill. Flexible pricing (hourly, annual, BYOL, private offers). Helps with cost management and governance & entitlement (control who can buy what, track licences).

A start-up wants the LOWEST-cost AWS Support plan that gives 24/7 phone access to AWS engineers for production issues. Which plan should it choose?

Business Support+ is the lowest-cost plan with 24/7 engineer access (from USD 29/month). Basic has no technical support cases.

A company needs a designated Technical Account Manager for proactive guidance, at the LOWEST cost. Which support plan should it choose?

Designated TAM starts at Enterprise Support. Unified Operations also has one, but costs much more.

Which service gives recommendations on idle resources, security-group ports open to the world, and service quotas that are close to their limits?

Best-practice checks across cost, security, limits, etc. โ†’ Trusted Advisor.

A company wants to buy a third-party firewall product that runs on AWS and pay for it through its AWS bill. Where should it look?

Third-party software, billed on your AWS bill โ†’ AWS Marketplace. Service Catalog is for your own approved products.

Recap ยท guess, then tapDomain 4 flash cards

Spot Instances (up to 90%)
Compute Savings Plan
AWS Pricing Calculator
AWS Budgets
AWS Cost Explorer
AWS Cost and Usage Report
Business Support+
Enterprise Support (and Unified Operations)
Inbound from internet; same-AZ private IP; AWS origin โ†’ CloudFront
Cost, Performance, Security, Fault tolerance, Service limits, Operational excellence
๐Ÿ

Final mock โ€” 20 mixed questions

Aim for 16+ correct

Mixed domains, like the real exam. Use the 3-step method: keyword โ†’ service โ†’ kill distractors.

1. Which AWS service lets a company define its infrastructure in a template and deploy the same environment repeatedly in several Regions?

Infrastructure as code templates โ†’ CloudFormation.

2. Which task is AWS responsible for under the shared responsibility model when a customer uses AWS Lambda?

Serverless: AWS handles OS + managed runtime. Code, IAM and data stay with the customer.

3. Which are benefits of AWS global infrastructure?

Low latency + data residency. Data never leaves a Region unless you move it; inter-Region transfer is charged; AZs are isolated.

4. Which service can a company use to centrally manage single sign-on access for its employees to multiple AWS accounts?

Workforce SSO across accounts โ†’ IAM Identity Center. Cognito is for your app's customers.

5. A company's website is hit by a large DDoS attack. It wants 24/7 access to AWS DDoS experts and protection against the extra scaling charges caused by the attack. What should it use?

Response team + DDoS cost protection = Shield Advanced. Standard is free and automatic but has neither.

6. Which pillar of the Well-Architected Framework includes the principle "maximise utilisation" to reduce the energy needed by a workload?

Environmental impact / energy โ†’ Sustainability.

7. A company wants an AWS-managed relational database that is MySQL-compatible, keeps six copies of data across three AZs, and offers higher performance than standard MySQL. Which service fits?

Aurora: MySQL/PostgreSQL-compatible, 6 copies across 3 AZs, faster than standard engines.

8. Which AWS service analyses CloudTrail events, VPC Flow Logs and DNS logs to detect compromised instances and malicious activity?

Threat detection from logs = GuardDuty ๐Ÿ•.

9. A company wants to move an application to AWS quickly without making any changes, then optimise later. Which migration strategy is this?

As-is, fast = Rehost (lift and shift).

10. Which storage is lost when an EC2 instance is stopped?

Instance store is ephemeral โ€” data is gone on stop, hibernate or terminate.

11. Which AWS service routes users to the application endpoint with the lowest latency and can fail over to a healthy endpoint using DNS health checks?

DNS with latency and failover routing policies + health checks โ†’ Route 53.

12. Which are benefits of AWS Organizations consolidated billing?

One bill + aggregated usage for volume tiers (plus shared RI / Savings Plans discounts).

13. A company needs to give a third-party auditor temporary access to resources in its AWS account without sharing long-term credentials. What is the BEST approach?

Cross-account IAM roles give temporary credentials with least privilege.

14. A company wants to analyse streaming clickstream data from its website in real time. Which service should collect the stream?

Real-time streaming ingestion โ†’ Kinesis.

15. Which benefit of cloud computing means a company no longer needs to buy servers for its expected peak load in advance?

Buying for peak in advance = guessing โ†’ Stop guessing capacity.

16. Where can a customer view AWS events and scheduled maintenance that may affect its own resources?

Personalised events affecting your resources โ†’ AWS Health Dashboard.

17. Which service gives a company a managed way to build, train and deploy its own custom machine learning models?

Custom models end to end โ†’ SageMaker AI. The others are pre-trained AI services.

18. Which service uses machine learning to recommend optimal EC2 instance types and sizes based on historical utilisation?

ML rightsizing for EC2, EBS, Lambda, ECS on Fargate โ†’ Compute Optimizer. (Trusted Advisor also flags idle resources.)

19. Which network control can explicitly DENY traffic from a specific IP address range to all instances in a subnet?

Deny rules at subnet level โ†’ Network ACL. Security groups have allow rules only.

20. A company wants to discover its on-premises servers, their utilisation and dependencies to plan a migration. Which service should it use?

Discovery = find servers and dependencies. Application Migration Service does the actual lift-and-shift.

Cheat sheet ยท read the night beforeKeyword โ†’ answer (1/2)

Who did it? (API calls)
โ†’
CloudTrail
Metrics / alarms
โ†’
CloudWatch
Config history / rules
โ†’
Config
AWS compliance reports
โ†’
Artifact
DDoS
โ†’
Shield
SQLi / XSS
โ†’
WAF
Threats in logs
โ†’
GuardDuty
Vulnerabilities (CVE)
โ†’
Inspector
PII in S3
โ†’
Macie
Root-cause investigation
โ†’
Detective
All findings in one place
โ†’
Security Hub
Encryption keys
โ†’
KMS
Dedicated HSM
โ†’
CloudHSM
Rotate secrets
โ†’
Secrets Manager
SSL/TLS certs
โ†’
ACM
Workforce SSO
โ†’
IAM Identity Center
App user sign-in
โ†’
Cognito
Account guardrails
โ†’
SCPs (Organizations)
Landing zone
โ†’
Control Tower
Best-practice checks
โ†’
Trusted Advisor
Events affecting you
โ†’
Health Dashboard
Report abuse
โ†’
Trust & Safety

Cheat sheet ยท read the night beforeKeyword โ†’ answer (2/2)

Serverless functions
โ†’
Lambda
Serverless containers
โ†’
Fargate
Kubernetes
โ†’
EKS
Simple VPS, fixed price
โ†’
Lightsail
Upload code, AWS runs it
โ†’
Elastic Beanstalk
NoSQL ms latency
โ†’
DynamoDB
In-memory cache
โ†’
ElastiCache
Data warehouse
โ†’
Redshift
Graph
โ†’
Neptune
SQL on S3
โ†’
Athena
Streaming
โ†’
Kinesis
ETL
โ†’
Glue
CDN
โ†’
CloudFront
DNS
โ†’
Route 53
Private line
โ†’
Direct Connect
Queue / decouple
โ†’
SQS
Push notifications
โ†’
SNS
Shared Linux files
โ†’
EFS
Cheapest archive
โ†’
Glacier Deep Archive
Hybrid storage cache
โ†’
Storage Gateway
Estimate cost
โ†’
Pricing Calculator
Spend alerts
โ†’
Budgets
Analyse spend
โ†’
Cost Explorer
3rd-party software
โ†’
Marketplace

NumbersThe few numbers worth memorising

11 nines

S3 durability (99.999999999%)

15 min

Max Lambda run time

2 min

Spot interruption warning

90% / 72% / 66%

Spot / EC2 Instance SP & Standard RI / Compute SP & Convertible RI

1 or 3 years

RI and Savings Plans terms

6

Well-Architected pillars ยท CAF perspectives ยท Trusted Advisor categories

7

Migration Rs

30 / 15 / 5 min

Critical response: Business+ / Enterprise / Unified Ops

30 / 90 / 180 days

Min. storage: IA / Glacier IR & Flexible / Deep Archive

50 TB

Max single S3 object (was 5 TB before Dec 2025)

53

DNS port โ†’ Route 53

700

Pass mark out of 1000

Exam dayYour game plan ๐ŸŽฎ

1

Before

Sleep. Eat. Online exam: clear desk, ID ready, run the system check early.

2

Pass 1

Answer what you know fast. Flag anything > 1 minute. Always pick something.

3

Pass 2

Come back to flagged ones. Eliminate. Prefer managed / serverless / least effort.

4

Final check

No blanks. Multiple response: did you pick the exact number asked?

Some questions are unscored experiments. A strange question? Don't panic โ€” it might not even count.
Don't change an answer unless you find a clear reason. First instinct is often right.
๐Ÿ†โ˜๏ธ

You've got this!

Re-run the quizzes with N until you score 90%+. Then book the exam.

Score so far is shown at the bottom bar ยท โ†บ resets it

START