AWS CLF-C02 Cheat Sheet 2026
A practical, foundational revision reference for the AWS Certified Cloud Practitioner exam.
Foundational · Broad AWS Literacy · Free to UseWhat This Cheat Sheet Covers
CLF-C02 tests broad AWS literacy — cloud concepts, security fundamentals, core service selection, and billing — rather than deep hands-on configuration. Domain 3 (Cloud Technology & Services) is the largest domain at 34%, yet many candidates over-study Domain 2 instead. Together, Domains 2 and 3 make up 64% of the exam, so this page weights its coverage accordingly.
High-Yield Concept Comparisons
CLF-C02 leans on knowing which service or model fits a given description. The format below mirrors how the exam phrases it: a scenario cue, and the service that matches.
IaaS vs PaaS vs SaaS
IaaS: You manage OS, applications, and runtime; AWS manages physical infrastructure (e.g., EC2).
PaaS: AWS manages underlying infrastructure and runtime/platform components while you focus on code and data (e.g., Elastic Beanstalk).
SaaS: Complete software application fully managed and delivered by provider.
Region vs AZ vs Edge Location
Region: Geographic area containing multiple isolated Availability Zones.
Availability Zone: One or more discrete data centers with redundant power and networking.
Edge Location: CloudFront point of presence used to cache content closer to end users.
Shared Responsibility Model
Security OF the Cloud (AWS): Physical data centers, hardware, hypervisors, global network infrastructure.
Security IN the Cloud (Customer): Customer data, IAM policies, network security groups, operating system patching on EC2.
IAM User vs Group vs Role
IAM User: Persistent identity with long-term credentials (password, access keys).
IAM Group: Collection of users sharing identical permission policies.
IAM Role: Identity assumed by users, apps, or services providing temporary credentials.
CloudTrail vs CloudWatch
CloudTrail: "Who did what, from where, and when" (API activity auditing & governance).
CloudWatch: "What is happening right now" (Operational metrics, logs, performance alarms).
Security Groups vs Network ACLs
Security Group: Instance-level firewall, stateful, supports ALLOW rules only.
Network ACL: Subnet-level firewall, stateless, supports both ALLOW and DENY rules.
Internet Gateway vs NAT Gateway
Internet Gateway: Path between VPC and public internet for resources with public IPs.
NAT Gateway: Allows private subnet instances outbound internet access while blocking inbound connection attempts.
EC2 Pricing Options
On-Demand: Short-term, irregular workloads with no commitment.
Savings Plans: Predictable, steady-state usage with flexible $/hr commitment (1 or 3 yrs).
Reserved Instances: Steady-state workloads requiring specific EC2 attribute commitments.
Spot Instances: Flexible, fault-tolerant workloads tolerant of interruptions.
Lambda vs Fargate vs ECS/EKS
Lambda: Event-driven serverless code execution with zero server management.
Fargate: Serverless compute engine for containers (no EC2 node management).
ECS / EKS: Managed container orchestration platforms running on EC2 or Fargate.
EBS vs EFS vs S3
EBS: Persistent block storage for EC2 instances, strictly AZ-scoped.
EFS: Scalable POSIX network file storage shared across multiple instances.
S3: Highly durable object storage accessible from anywhere via HTTP/API.
S3 Storage Classes & Retrieval
Standard / Standard-IA: Active data (Instant) / Infrequent data (Millisecond).
Intelligent-Tiering: Automatic cost optimization for unknown access patterns.
Glacier Instant: Archive data requiring millisecond retrieval.
Glacier Flexible / Deep Archive: Retrieval in minutes-to-hours / Hours (lowest cost).
RDS vs DynamoDB vs Redshift
RDS: Managed relational database supporting SQL and complex table joins.
DynamoDB: Managed NoSQL key-value database delivering single-digit ms latency.
Redshift: Petabyte-scale cloud data warehouse optimized for OLAP analytics.
CloudTrail vs Config vs Trusted Advisor
CloudTrail: Immutable audit log recording all account-wide API actions.
AWS Config: Tracks resource configuration history, relationships, and compliance.
Trusted Advisor: Automated best-practice guidance for cost, security, and performance.
Pricing Calculator vs Cost Explorer vs Budgets
Pricing Calculator: Estimate architecture deployment costs BEFORE building.
Cost Explorer: Analyze, track, and visualize historical spend and usage AFTER deployment.
AWS Budgets: Set custom financial thresholds and receive automated alerts.
AWS Support Plans
Basic Support: Included for all AWS customers with account assistance, documentation, AWS Health, and core Trusted Advisor checks.
Business Support+: 24/7 access to AWS experts with AI-powered troubleshooting and faster response times for production issues.
Enterprise Support: Business-critical support with designated Technical Account Manager (TAM) guidance and faster response targets.
Amazon Bedrock vs Amazon SageMaker
Amazon Bedrock: Build generative AI apps using managed Foundation Models via unified APIs.
Amazon SageMaker: Complete platform to build, train, and deploy custom machine learning models.
Top CLF-C02 Exam Traps
An Edge Location is a point of presence for CloudFront content delivery — it is not an AZ or a Region.
Shared responsibility varies by service model — infrastructure patching for managed services like RDS is handled by AWS, whereas EC2 OS patching is handled by the customer.
CloudTrail logs API activity ("who did what"); CloudWatch monitors operational metrics and logs — do not confuse them.
Spot Instances offer steep discounts but can be reclaimed by AWS with a 2-minute interruption notice when capacity is needed.
Security Groups are stateful (return traffic auto-allowed); Network ACLs are stateless (return traffic requires explicit rules).
Domain 3 (Cloud Technology & Services) carries the highest exam weight at 34% — focus study time accordingly.
Basic Support includes access to core Trusted Advisor checks; full checks are unlocked on higher paid support plans.
AWS Secrets Manager automatically rotates database credentials; Parameter Store requires manual configuration or custom integration.
NAT Gateway enables private subnet resources to initiate outbound internet access — external connections cannot initiate inbound requests to it.
VPC Peering routes traffic directly between VPCs but does not support edge-to-edge transitive routing across multiple peered connections.
IAM / Storage / Support Quick Reference
IAM Essentials
- AWS account root user has complete access — secure with MFA and avoid routine tasks
- Assign permissions to IAM Groups rather than individual users
- Use IAM Roles for temporary credentials assigned to workloads and services
- Enforce the Principle of Least Privilege across all access management
Storage at a Glance
- S3 = scalable API-driven object storage
- EBS = high-performance block storage scoped to a specific AZ
- EFS = POSIX-compliant shared file storage for Linux compute resources
- Glacier = secure, durable archive options with flexible retrieval speeds
Support Plans Overview
- Basic: free account/billing support & core Trusted Advisor access
- Business Support+: 24/7 technical access & full Trusted Advisor checks
- Enterprise Support: designated Technical Account Manager (TAM) & rapid critical response targets
Your 7-Day CLF-C02 Exam Sprint
Day 1–2: Cloud Concepts + Global Infrastructure — Master cloud economics, trade-offs, and Region vs AZ vs Edge Location definitions.
Day 3: Security & Shared Responsibility — Accountable for 30% of the exam. Learn the customer vs AWS boundary and core security services.
Day 4: Compute + Storage + Databases — Focus on EC2 pricing scenarios, S3 storage class decision trees, and primary database use cases.
Day 5: Networking + Management + Billing — Master Security Groups vs NACLs, Cost Explorer, Budgets, and Support tier structures.
Day 6: AI/ML + Full Practice Exam — Review managed Bedrock vs SageMaker features, then complete a timed 25-question practice test.
Day 7: Targeted Review & Rest — Revisit missed practice questions and refresh key definitions.
Ready to Test Your CLF-C02 Knowledge?
Studying content builds recall. A practice exam is what tells you if you're actually ready.
Frequently Asked Questions
What is the AWS CLF-C02 Cheat Sheet?
A condensed foundational reference covering the concepts, comparisons, and traps most commonly tested on the AWS Certified Cloud Practitioner exam.
Is the CLF-C02 Cheat Sheet free?
Yes. This page and the downloadable PDF are both free to use.
Can I download the CLF-C02 Cheat Sheet as a PDF?
Yes, use the download button at the top of this page to get a print-friendly PDF version.
What topics does the cheat sheet cover?
Cloud concepts and value proposition, AWS global infrastructure, security and shared responsibility, core compute and storage services, databases, networking, management and governance, billing and support, and generative AI on AWS.
Is a cheat sheet enough to pass CLF-C02?
No. CLF-C02 covers broad AWS literacy, so a cheat sheet works best alongside practice exams — not as your only study material.
Where can I practice CLF-C02 questions?
Take CloudExamPro's free 25-question CLF-C02 practice exam to test your knowledge and identify the areas you should review before taking the full exam.
Study Smarter. Practice Smarter.
Use this cheat sheet for fast revision, then confirm what you know with a practice exam.