AWS CLF-C02 Cheat Sheet 2026

A practical, foundational revision reference for the AWS Certified Cloud Practitioner exam.

Foundational · Broad AWS Literacy · Free to Use
65Questions
90 minDuration
700/1000Passing Score
$100Exam Cost
25 QsFree Practice
3 YearsValidity
Exam Domains

What This Cheat Sheet Covers

CLF-C02 tests broad AWS literacy — cloud concepts, security fundamentals, core service selection, and billing — rather than deep hands-on configuration. Domain 3 (Cloud Technology & Services) is the largest domain at 34%, yet many candidates over-study Domain 2 instead. Together, Domains 2 and 3 make up 64% of the exam, so this page weights its coverage accordingly.

24%Cloud Concepts
30%Security & Compliance
34%Cloud Technology & Services
12%Billing, Pricing & Support
Core Reference

High-Yield Concept Comparisons

CLF-C02 leans on knowing which service or model fits a given description. The format below mirrors how the exam phrases it: a scenario cue, and the service that matches.

Cloud Concepts

IaaS vs PaaS vs SaaS

IaaS: You manage OS, applications, and runtime; AWS manages physical infrastructure (e.g., EC2).

PaaS: AWS manages underlying infrastructure and runtime/platform components while you focus on code and data (e.g., Elastic Beanstalk).

SaaS: Complete software application fully managed and delivered by provider.

Global Infrastructure

Region vs AZ vs Edge Location

Region: Geographic area containing multiple isolated Availability Zones.

Availability Zone: One or more discrete data centers with redundant power and networking.

Edge Location: CloudFront point of presence used to cache content closer to end users.

Trap: An Edge Location is NOT an Availability Zone or Region.
Security

Shared Responsibility Model

Security OF the Cloud (AWS): Physical data centers, hardware, hypervisors, global network infrastructure.

Security IN the Cloud (Customer): Customer data, IAM policies, network security groups, operating system patching on EC2.

IAM

IAM User vs Group vs Role

IAM User: Persistent identity with long-term credentials (password, access keys).

IAM Group: Collection of users sharing identical permission policies.

IAM Role: Identity assumed by users, apps, or services providing temporary credentials.

Monitoring

CloudTrail vs CloudWatch

CloudTrail: "Who did what, from where, and when" (API activity auditing & governance).

CloudWatch: "What is happening right now" (Operational metrics, logs, performance alarms).

Networking

Security Groups vs Network ACLs

Security Group: Instance-level firewall, stateful, supports ALLOW rules only.

Network ACL: Subnet-level firewall, stateless, supports both ALLOW and DENY rules.

Trap: NACL return traffic requires an explicit rule — it is not auto-allowed.
Networking

Internet Gateway vs NAT Gateway

Internet Gateway: Path between VPC and public internet for resources with public IPs.

NAT Gateway: Allows private subnet instances outbound internet access while blocking inbound connection attempts.

Compute

EC2 Pricing Options

On-Demand: Short-term, irregular workloads with no commitment.

Savings Plans: Predictable, steady-state usage with flexible $/hr commitment (1 or 3 yrs).

Reserved Instances: Steady-state workloads requiring specific EC2 attribute commitments.

Spot Instances: Flexible, fault-tolerant workloads tolerant of interruptions.

Compute

Lambda vs Fargate vs ECS/EKS

Lambda: Event-driven serverless code execution with zero server management.

Fargate: Serverless compute engine for containers (no EC2 node management).

ECS / EKS: Managed container orchestration platforms running on EC2 or Fargate.

Storage

EBS vs EFS vs S3

EBS: Persistent block storage for EC2 instances, strictly AZ-scoped.

EFS: Scalable POSIX network file storage shared across multiple instances.

S3: Highly durable object storage accessible from anywhere via HTTP/API.

Storage

S3 Storage Classes & Retrieval

Standard / Standard-IA: Active data (Instant) / Infrequent data (Millisecond).

Intelligent-Tiering: Automatic cost optimization for unknown access patterns.

Glacier Instant: Archive data requiring millisecond retrieval.

Glacier Flexible / Deep Archive: Retrieval in minutes-to-hours / Hours (lowest cost).

Database

RDS vs DynamoDB vs Redshift

RDS: Managed relational database supporting SQL and complex table joins.

DynamoDB: Managed NoSQL key-value database delivering single-digit ms latency.

Redshift: Petabyte-scale cloud data warehouse optimized for OLAP analytics.

Governance

CloudTrail vs Config vs Trusted Advisor

CloudTrail: Immutable audit log recording all account-wide API actions.

AWS Config: Tracks resource configuration history, relationships, and compliance.

Trusted Advisor: Automated best-practice guidance for cost, security, and performance.

Billing

Pricing Calculator vs Cost Explorer vs Budgets

Pricing Calculator: Estimate architecture deployment costs BEFORE building.

Cost Explorer: Analyze, track, and visualize historical spend and usage AFTER deployment.

AWS Budgets: Set custom financial thresholds and receive automated alerts.

Support

AWS Support Plans

Basic Support: Included for all AWS customers with account assistance, documentation, AWS Health, and core Trusted Advisor checks.

Business Support+: 24/7 access to AWS experts with AI-powered troubleshooting and faster response times for production issues.

Enterprise Support: Business-critical support with designated Technical Account Manager (TAM) guidance and faster response targets.

AI/ML

Amazon Bedrock vs Amazon SageMaker

Amazon Bedrock: Build generative AI apps using managed Foundation Models via unified APIs.

Amazon SageMaker: Complete platform to build, train, and deploy custom machine learning models.

Watch For These

Top CLF-C02 Exam Traps

✕

An Edge Location is a point of presence for CloudFront content delivery — it is not an AZ or a Region.

✕

Shared responsibility varies by service model — infrastructure patching for managed services like RDS is handled by AWS, whereas EC2 OS patching is handled by the customer.

✕

CloudTrail logs API activity ("who did what"); CloudWatch monitors operational metrics and logs — do not confuse them.

✕

Spot Instances offer steep discounts but can be reclaimed by AWS with a 2-minute interruption notice when capacity is needed.

✕

Security Groups are stateful (return traffic auto-allowed); Network ACLs are stateless (return traffic requires explicit rules).

✕

Domain 3 (Cloud Technology & Services) carries the highest exam weight at 34% — focus study time accordingly.

✕

Basic Support includes access to core Trusted Advisor checks; full checks are unlocked on higher paid support plans.

✕

AWS Secrets Manager automatically rotates database credentials; Parameter Store requires manual configuration or custom integration.

✕

NAT Gateway enables private subnet resources to initiate outbound internet access — external connections cannot initiate inbound requests to it.

✕

VPC Peering routes traffic directly between VPCs but does not support edge-to-edge transitive routing across multiple peered connections.

Memorize This

IAM / Storage / Support Quick Reference

IAM Essentials

  • AWS account root user has complete access — secure with MFA and avoid routine tasks
  • Assign permissions to IAM Groups rather than individual users
  • Use IAM Roles for temporary credentials assigned to workloads and services
  • Enforce the Principle of Least Privilege across all access management

Storage at a Glance

  • S3 = scalable API-driven object storage
  • EBS = high-performance block storage scoped to a specific AZ
  • EFS = POSIX-compliant shared file storage for Linux compute resources
  • Glacier = secure, durable archive options with flexible retrieval speeds

Support Plans Overview

  • Basic: free account/billing support & core Trusted Advisor access
  • Business Support+: 24/7 technical access & full Trusted Advisor checks
  • Enterprise Support: designated Technical Account Manager (TAM) & rapid critical response targets
Exam Strategy

Your 7-Day CLF-C02 Exam Sprint

Day 1–2: Cloud Concepts + Global Infrastructure — Master cloud economics, trade-offs, and Region vs AZ vs Edge Location definitions.

Day 3: Security & Shared Responsibility — Accountable for 30% of the exam. Learn the customer vs AWS boundary and core security services.

Day 4: Compute + Storage + Databases — Focus on EC2 pricing scenarios, S3 storage class decision trees, and primary database use cases.

Day 5: Networking + Management + Billing — Master Security Groups vs NACLs, Cost Explorer, Budgets, and Support tier structures.

Day 6: AI/ML + Full Practice Exam — Review managed Bedrock vs SageMaker features, then complete a timed 25-question practice test.

Day 7: Targeted Review & Rest — Revisit missed practice questions and refresh key definitions.

Ready to Test Your CLF-C02 Knowledge?

Studying content builds recall. A practice exam is what tells you if you're actually ready.

FAQ

Frequently Asked Questions

What is the AWS CLF-C02 Cheat Sheet?

A condensed foundational reference covering the concepts, comparisons, and traps most commonly tested on the AWS Certified Cloud Practitioner exam.

Is the CLF-C02 Cheat Sheet free?

Yes. This page and the downloadable PDF are both free to use.

Can I download the CLF-C02 Cheat Sheet as a PDF?

Yes, use the download button at the top of this page to get a print-friendly PDF version.

What topics does the cheat sheet cover?

Cloud concepts and value proposition, AWS global infrastructure, security and shared responsibility, core compute and storage services, databases, networking, management and governance, billing and support, and generative AI on AWS.

Is a cheat sheet enough to pass CLF-C02?

No. CLF-C02 covers broad AWS literacy, so a cheat sheet works best alongside practice exams — not as your only study material.

Where can I practice CLF-C02 questions?

Take CloudExamPro's free 25-question CLF-C02 practice exam to test your knowledge and identify the areas you should review before taking the full exam.

Study Smarter. Practice Smarter.

Use this cheat sheet for fast revision, then confirm what you know with a practice exam.

Limited-time offer · ends in --Days:--Hrs:--Min:--Sec
Get Instant Access