CloudExamPro · Premium Edition 2026
AWS Certified Cloud Practitioner

CLF-C02 Premium
Strategy Guide

Pass on your first attempt

Pattern recognition. Decision matrices. Zero wasted study time.

The surgical playbook for CLF-C02 — decoded and structured for your use.

50
Exam Traps
100
Trigger Words
16
Decision Matrices
13
Chapters & Modules
FOREWORD
The Blueprint
How to use this guide to pass efficiently

This Is Not a Textbook

This guide is built around one objective: help you earn the certification quickly, cleanly, and on your first attempt. That means no filler, no AWS encyclopedia, and no walls of text about infrastructure you'll never touch. Instead, you get the patterns that appear on this exam, decoded into decision rules you can apply in the exam chair.

Many capable people fail this exam not because they don't know AWS, but because they don't know how AWS writes the questions. This guide teaches you to read the scenarios the way the exam intends.

What Makes This Different

FeatureStandard GuidesThis Guide
ApproachTeach AWS theoryTrain exam pattern recognition
TrapsRarely mentioned50 traps catalogued with distinction logic
MemoryBullet listsRhythmic anchor cadence — spoken recall
DecisionsParagraphs16 Decision Matrices — one-word triggers
Last DayReview notes24-Hour Cram Sheet — ultra-condensed

The Exam in 60 Seconds

  • 65 questions · 90 minutes — Passing score: approximately 700/1000
  • 4 domains: Cloud Concepts 24% | Security 30% | Technology 34% | Billing 12%
  • Approximately 83 seconds per question — pattern recognition reduces this significantly
  • Some questions are unscored pilot questions — answer every one as if it counts

Your 14-Day Study Plan

DaysFocusPriority
Days 1–3Chapters 1 + 4 — 36% of examFastest return on study time
Days 4–7Chapter 2 — Security (30%)The domain that rewards pattern work most
Days 8–11Chapter 3 — Technology (34%)Use Decision Matrices every session
Day 12Chapter 5 — Elimination PlaybookRehearse high-confidence eliminators
Day 13Chapter 6 + Module CRhythmic Anchors aloud + Cram Sheet review
Day 14EXAM DAY — Bonus 3 Morning-Of ChecklistExecute
CHAPTER 1
Cloud Concepts
Domain 1 · 24% of Exam Score
Instructor's Note

Cloud Concepts is often underestimated because it sounds conceptual. In practice, AWS embeds precise vocabulary into scenario questions, and small distinctions — like the difference between elasticity and scalability — determine whether an answer is correct. This chapter builds the vocabulary foundation you will rely on across all four domains.

1.1 The Six Advantages of Cloud Computing

AWS defines six core benefits. Two of them — economies of scale and trading fixed costs for variable costs — sound similar but describe different financial mechanisms.

BenefitWhat It MeansHow AWS Tests It
Trade fixed expense for variable expenseReplace upfront capital expenditure (CapEx) with pay-as-you-go operational expenditure (OpEx).Scenarios mentioning no upfront investment or CapEx reduction
Benefit from massive economies of scaleAWS purchases hardware in aggregate volume, reducing variable costs for customers.Scenarios mentioning lower variable costs or bulk purchasing
Stop guessing capacityProvision resources based on actual demand rather than forecasts. No idle servers.Scenarios mentioning over-provisioning or right-sizing
Increase speed and agilityLaunch resources in minutes instead of weeks. Faster experimentation and time-to-market.Scenarios mentioning rapid deployment or faster innovation
Stop spending on data centersFocus on your product rather than managing physical infrastructure.Scenarios mentioning undifferentiated heavy lifting
Go global in minutesDeploy applications across multiple geographic Regions quickly.Scenarios mentioning global reach or low-latency deployment
Common Misconception

Economies of scale does not mean "eliminates upfront costs." That describes trading fixed for variable.

  • Economies of scale = AWS's aggregate purchasing power lowers your variable costs.
  • Trade fixed for variable = You replace CapEx with OpEx. No large upfront purchase.

AWS places both as answer choices in the same question. They are distinct concepts.

1.2 Core Vocabulary: Elasticity, Scalability, Reliability, Durability

These four terms appear frequently and are commonly confused. Each describes a different system characteristic.

TermPrecise DefinitionKey Distinction
ElasticityAutomatically provision and release resources based on demand. Bidirectional and automatic.Automatically scales in AND out
ScalabilityAbility to grow to handle increased demand. One-directional growth.Grows to meet demand
ReliabilityAutomatically recover from failure and consistently meet performance expectations.Recovers from failure
DurabilityLong-term data persistence. Data does not disappear or become corrupted.Data persists over time

How to Distinguish Them in Scenarios

Scenario LanguageCorrect AnswerReasoning
Automatically provision AND release capacityElasticityBidirectional and automatic
Grow to handle increasing trafficScalabilityGrowth without automatic release
Recover from failure consistentlyReliabilityRecovery is the key attribute
Data persists with 11 nines of durabilityDurabilityData survival, not system recovery

1.3 AWS Well-Architected Framework — Six Pillars

The Well-Architected Framework provides design principles for building on AWS. The exam tests whether you can map a design goal to the correct pillar.

PillarDesign FocusScenario Trigger
Operational ExcellenceRun and monitor systems to deliver business value. Continuously improve processes.Improve processes / automate operations
SecurityProtect information, systems, and assets. Enable traceability. Apply least privilege.Protect data / traceability / least privilege
ReliabilityEnsure a system performs its intended function correctly and consistently. Recover from failure.Recover from failure / test recovery
Performance EfficiencyUse computing resources efficiently. Adopt serverless where appropriate.Serverless / right resource type
Cost OptimizationAvoid unnecessary costs. Analyze spending and eliminate waste.Analyze spend / reduce cost
SustainabilityMinimize environmental impact of cloud workloads.Carbon footprint / environmental impact
Common Misconception

"Test recovery procedures" sounds like an operational activity, but it belongs to the Reliability pillar. The Reliability pillar's design principle is "Automatically recover from failure," and testing recovery is part of that principle.

"Continuously improve processes" belongs to Operational Excellence.

These two are the most frequently swapped pillar concepts in exam questions.

1.4 AWS Global Infrastructure

AWS's global infrastructure consists of three nested layers, each serving a distinct purpose.

ComponentDescriptionTypical Count
RegionGeographic area containing multiple, isolated Availability Zones.30+ globally
Availability Zone (AZ)One or more discrete data centers with redundant power, networking, and connectivity.2–6 per Region
Edge LocationsSites used by CloudFront and Route 53 to cache content closer to users.Hundreds globally
Key Distinction
  • Multi-AZ deployment provides high availability within a Region. AZs have independent power and networking.
  • Multi-Region deployment provides geographic fault tolerance for disasters affecting an entire Region.
  • Edge Locations are more numerous than AZs, which are more numerous than Regions.
Common Misconception

If a scenario mentions "natural disaster" or "geographic redundancy," the correct answer is multiple Regions.

Availability Zones are isolated from each other for local failures, but they share the same geographic area. A regional disaster affects all AZs in that Region.

1.5 AWS Cloud Adoption Framework (CAF) — Six Perspectives

The AWS CAF provides guidance for organizations planning cloud adoption. The exam tests whether you can identify which perspective addresses a given concern.

PerspectiveFocus AreaScenario Trigger
BusinessBusiness value, ROI, strategic alignmentExecutive buy-in, business case
PeopleOrganizational change, skills, cultureTeam training, agile adoption
GovernanceRisk management, portfolio, data governanceCompliance, risk controls
PlatformCloud architecture, infrastructure as codeArchitecture standards, IaC
SecurityIdentity, detection, protection, responseIAM at scale, threat detection
OperationsDay-to-day operations, event managementOperational processes, monitoring

1.6 Migration Strategies — The Seven Rs

When organizations migrate workloads to AWS, they choose from seven common strategies. The exam tests whether you can identify which strategy matches a described approach.

StrategyDescriptionScenario Trigger
Rehost (Lift and Shift)Move applications as-is to AWS without changes.As-is / no changes
ReplatformMake limited optimizations without changing core architecture.Optimize without code changes
Refactor (Re-architect)Redesign applications using cloud-native features.Microservices / cloud-native redesign
RepurchaseReplace with a SaaS solution.Replace with SaaS
RetireDecommission applications no longer needed.Decommission / shut down
RetainKeep applications on-premises for now.Keep on-premises / not ready to migrate
RelocateMove infrastructure without modification, often using VMware.Move as-is / VMware migration
Chapter 1 — Key Takeaways
  • Economies of scale lowers variable costs; trading fixed for variable eliminates CapEx. These are distinct benefits.
  • Elasticity is automatic and bidirectional. Scalability is growth without automatic release.
  • "Test recovery" maps to Reliability. "Improve processes" maps to Operational Excellence.
  • Multi-AZ provides high availability within a Region. Multi-Region provides geographic disaster tolerance.
  • Rehost = as-is. Replatform = optimize without code changes. Refactor = redesign.
⚡ Domain 1 Complete
Domain 1: Cloud Concepts Covered — Now Test It

You have the vocabulary. Can you apply it under exam pressure? AWS phrases questions in ways that turn familiar concepts into distractors. Reading is only half the preparation.

  • Domain-specific questions targeting Cloud Concepts distinctions
  • Instant score breakdown — see exactly where you lose points
  • Explanations written in the same instructor voice as this guide
  • Built for CLF-C02's question style — no generic filler
Test Your Domain 1 Readiness → Designed specifically for CLF-C02 · Practice smarter, pass faster.
CHAPTER 2
Security & Compliance
Domain 2 · 30% of Exam Score
Instructor's Note

Security and Compliance represents the second-largest domain on the exam. The Shared Responsibility Model appears in multiple questions, sometimes directly and sometimes as context for a scenario. Understanding the boundary between AWS responsibilities and customer responsibilities is essential before studying individual security services.

2.1 The Shared Responsibility Model

The Shared Responsibility Model defines what AWS manages and what the customer manages. This concept appears directly in exam questions and also provides context for questions about specific services.

Simple Mental Model

Security OF the cloud = AWS. Security IN the cloud = Customer.

A useful heuristic: anything you configure in the AWS Console is your responsibility. Anything that lives in the data center is AWS's responsibility.

ResponsibilityTypically Managed ByExamples
Physical securityAWSData center access, hardware disposal, facility security
Hypervisor and virtualization layerAWSThe software layer beneath EC2 instances
Managed service operating systemsAWSRDS database OS, Lambda runtime environment
Automated RDS backup mechanismAWSAWS provides the backup mechanism. Customer configures retention period.
IAM configurationCustomerUsers, roles, groups, policies, MFA settings
Guest operating system patchingCustomerEC2 instance OS updates
Data encryption choicesCustomerWhether to enable encryption, which keys to use
Security group and NACL rulesCustomerFirewall configuration for EC2 and subnets
Application codeCustomerLambda function code, application logic

How the Boundary Shifts Based on Service Type

The division of responsibility changes depending on whether a service is managed by AWS or self-managed. This distinction is frequently tested.

ScenarioResponsibilityReasoning
Patching the RDS database OSAWSRDS is a managed service. AWS owns and patches the OS.
Configuring RDS backup retention periodCustomerConfiguration choices remain with the customer.
Creating IAM users and assigning rolesCustomerIdentity configuration is always the customer's responsibility.
Securing the physical S3 hardwareAWSPhysical infrastructure is always AWS's responsibility.
Configuring security groups for EC2CustomerFirewall rules are customer-configured.
Patching the EC2 guest operating systemCustomerEC2 is self-managed at the OS level.
Common Misconception

For managed services like RDS, AWS manages the backup infrastructure — the automated mechanism that creates backups. However, the customer configures the backup retention period and whether automated backups are enabled.

If a question asks who is responsible for configuring backups, the answer is the customer. If it asks who provides the backup mechanism, the answer is AWS.

2.2 AWS Identity and Access Management (IAM)

IAM controls authentication (who can sign in) and authorization (what they can do). The exam tests whether you know when to use each IAM entity type.

EntityUse CaseCredentials
IAM UserA specific person or application that needs long-term AWS access.Username/password, access keys
IAM RoleAn entity that assumes temporary permissions. Used by EC2, Lambda, and federated users.Temporary credentials via STS
IAM GroupA collection of users who share the same permissions.No credentials; policies only
IAM PolicyA JSON document defining permissions.Attached to users, groups, or roles
Common Misconception

Applications running on EC2 should use IAM Roles, not IAM Users.

Roles provide temporary credentials that rotate automatically through the AWS Security Token Service (STS). Creating an IAM user with long-term access keys for an application is a security anti-pattern and is typically an incorrect answer on the exam.

2.3 Security Services — What Each Service Does

The exam tests whether you can select the correct security service for a described scenario. Each service has a distinct primary function.

ServicePrimary FunctionDoes It Block Traffic?
AWS Shield StandardAutomatic protection against common DDoS attacks at Layers 3 and 4.Yes (automatic)
AWS Shield AdvancedEnhanced DDoS protection with access to the Shield Response Team (SRT).Yes, plus SRT
AWS WAFFilter HTTP/HTTPS traffic to block SQL injection, XSS, and bot traffic (when configured).Yes (when configured)
Amazon GuardDutyContinuous threat detection using machine learning. Identifies malicious activity.No — detects only
Amazon InspectorAutomated vulnerability scanning for EC2 instances and container images.No — assesses only
Amazon MacieDiscovers and classifies sensitive data (PII, PHI) stored in Amazon S3.No — discovers only
AWS KMSCreate and manage encryption keys used to encrypt data at rest.N/A
AWS Secrets ManagerStore and automatically rotate database credentials and API keys.N/A
AWS CloudTrailRecord API calls for audit — who did what and when.No — logs only
AWS ArtifactSelf-service access to AWS compliance reports (SOC, PCI, ISO).N/A

How to Select the Right Security Service

Scenario LanguageCorrect ServiceReasoning
Who deleted or modified a resourceAWS CloudTrailAPI audit log records identity and action
Compliance report (SOC, PCI, ISO)AWS ArtifactSelf-service compliance documentation
Threat detection / malicious activityAmazon GuardDutyContinuous threat identification
Vulnerability scan / CVE assessmentAmazon InspectorAutomated vulnerability scanning
Sensitive data in S3 / PII / PHIAmazon MacieData discovery and classification in S3
SQL injection / XSS / bot trafficAWS WAFApplication-layer HTTP filtering (when configured)
DDoS flood / network attackAWS ShieldNetwork-layer DDoS protection
Access to Shield Response Team (SRT)AWS Shield Advanced + Business Support+SRT requires both Shield Advanced and Business Support or higher

2.4 Network Security: Security Groups vs Network ACLs

Both control network traffic, but they operate at different levels and have different behaviors. The exam tests whether you know which one applies to a given requirement.

PropertySecurity GroupNetwork ACL
Applies toInstance level (e.g., EC2, RDS)Subnet level
StateStateful — return traffic is automatically allowedStateless — return traffic must be explicitly allowed
Rule typesAllow rules onlyAllow and deny rules
EvaluationAll rules evaluated before decisionRules evaluated in numerical order
Memory Aid

Security Group = Stateful + Instance-level

Network ACL = Stateless + Subnet-level

These four attributes are the most commonly tested distinctions between the two.

2.5 Identity Federation and Single Sign-On

Two services handle different identity scenarios. Understanding their intended users prevents confusion.

ServiceUse CaseUser Type
Amazon CognitoSign-up and sign-in for your application's end users (customers).External users
AWS IAM Identity CenterSingle sign-on for workforce users across multiple AWS accounts and business applications.Employees / workforce
Simple Distinction

Cognito = your customers. IAM Identity Center = your employees.

Scenario Practice

ScenarioCorrect AnswerReasoning
Security team needs to identify who deleted a production database.AWS CloudTrailCloudTrail records API activity and identity.
Compliance team needs to download a PCI DSS attestation.AWS ArtifactArtifact provides self-service compliance reports.
An EC2 instance is communicating with a known malicious IP.Amazon GuardDutyGuardDuty detects threats and alerts.
Chapter 2 — Key Takeaways
  • RDS OS patching = AWS responsibility. RDS backup retention configuration = customer responsibility.
  • EC2 applications should use IAM Roles, not IAM Users.
  • GuardDuty detects. Inspector scans. WAF blocks HTTP (when configured). Shield blocks DDoS.
  • CloudTrail records WHO did WHAT. CloudWatch monitors performance metrics. AWS Config tracks configuration compliance.
  • Security Group = stateful + instance-level. Network ACL = stateless + subnet-level.
  • SRT access requires Shield Advanced + Business Support or higher.
  • Cognito = external customer identity. IAM Identity Center = workforce SSO.
⚡ Domain 2 Complete
Security & Compliance Covered — Can You Score It Under Pressure?

Domain 2 is 30% of your exam — roughly 20 questions you cannot afford to misread. You've learned the Shared Responsibility splits, security service verbs, and stateful vs stateless. Now the real question: are those patterns automatic yet?

  • Shared Responsibility scenarios phrased exactly like the real exam
  • GuardDuty vs Inspector vs WAF discrimination drills
  • IAM Role vs User trap questions — the way AWS actually writes them
  • CloudTrail vs CloudWatch vs Config separation under timed pressure
Launch Domain 2 Security Quiz → 390+ questions across all 4 domains · 6 full exams · $29.99 per certification · one-time payment
CHAPTER 3
Cloud Technology & Services
Domain 3 · 34% of Exam Score
Instructor's Note

This is the largest domain on the exam, and it rewards a specific skill: recognizing which service or feature fits a described requirement. You do not need deep architectural knowledge. You need to distinguish services that sound similar but solve different problems.

3.1 EC2 Purchasing Options

Amazon EC2 offers several purchasing models, each designed for a different workload pattern. The exam tests whether you can match a described workload to the most cost-effective option.

OptionCommitmentTypical DiscountBest For
On-DemandNoneBaseline rateUnpredictable or short-term workloads, development and testing
Reserved Instances (Standard)1 or 3 yearsUp to 72%Steady-state workloads with predictable instance families
Reserved Instances (Convertible)1 or 3 yearsLower than StandardSteady-state workloads where you may need to change instance family
Spot InstancesNoneUp to 90%Fault-tolerant, stateless, or batch workloads
Savings Plans1 or 3 years (hourly commitment)Up to 72%Flexible commitment across EC2, Lambda, and Fargate
Dedicated HostsVariesBYOLPhysical server isolation for licensing or compliance requirements

How to Select the Right Purchasing Option

Scenario LanguageCorrect OptionReasoning
Cannot tolerate interruption / steady-state 24/7Reserved InstancesSpot's interruption risk eliminates it
Cheapest option / workload can be interruptedSpot InstancesUp to 90% discount in exchange for interruption risk
No commitment / short-term / unpredictableOn-DemandNo upfront commitment required
Maximum savings / 3-year / fixed instance familyStandard Reserved Instance (All Upfront)Deepest discount with commitment
Physical server / license compliance / BYOLDedicated HostPhysical isolation for licensing requirements
Important Distinction: Lambda Invocation Models

Standard Lambda synchronous invocations are limited to 15 minutes. This is the limit tested on CLF-C02.

However, Lambda Managed Instances support up to 90 minutes for asynchronous invocations. Event Source Mapping invocations (except Amazon MQ and DocumentDB) also support 90 minutes on Managed Instances.

Exam guidance: For standard Lambda functions, 15 minutes is the limit. If a scenario describes a job exceeding 15 minutes and does not mention Managed Instances, the correct alternative is Fargate or AWS Batch.

3.2 Amazon S3 Storage Classes

S3 offers multiple storage classes, each optimized for different access patterns and cost requirements. The exam tests whether you can select the appropriate class for a described scenario.

Storage ClassDesigned ForRetrieval Options
S3 StandardFrequently accessed dataMillisecond access, no restore needed
S3 Standard-IAInfrequently accessed data requiring immediate accessMillisecond access, no restore needed
S3 Intelligent-TieringUnknown or changing access patternsAutomatic tiering; no retrieval fees
S3 Glacier Instant RetrievalLong-term archive accessed quarterly, requiring immediate accessMillisecond access; no restore request required
S3 Glacier Flexible RetrievalArchive data accessed 1–2 times per year, hours acceptableExpedited: 1–5 min (objects <250MB)
Standard: 3–5 hours
Bulk: 5–12 hours
S3 Glacier Deep ArchiveCompliance archives, long-term retention (7–10+ years)Standard: Within 12 hours
Bulk: Within 48 hours
Expedited not available
Common Misconception: Glacier Retrieval Is Class-Specific

Do not assume all S3 Glacier storage classes share the same retrieval characteristics.

  • S3 Glacier Instant Retrieval provides real-time access with no restore request. It is designed for data accessed once per quarter.
  • S3 Glacier Flexible Retrieval and S3 Glacier Deep Archive require a restore operation before data can be accessed.
  • Expedited retrieval is only available for S3 Glacier Flexible Retrieval, not for Deep Archive.

If a scenario requires immediate access without a restore step, Glacier Instant Retrieval is the correct choice. If hours are acceptable and cost matters more, Glacier Flexible (Bulk) or Deep Archive (Bulk) applies.

3.3 Database Services

AWS offers purpose-built database services. The exam tests whether you can identify the right service for a described data model or workload.

ServiceDatabase TypeTypical Use Case
Amazon RDSManaged relational (SQL)Traditional applications, ERP, CRM, e-commerce
Amazon AuroraCloud-native relationalMySQL/PostgreSQL-compatible with higher performance
Amazon DynamoDBNoSQL key-value and documentServerless, single-digit millisecond performance at scale
Amazon RedshiftData warehousePetabyte-scale analytics and business intelligence
Amazon ElastiCacheIn-memory cacheMicrosecond latency caching with Redis or Memcached
Amazon NeptuneGraph databaseHighly connected datasets, fraud detection, social networks
Amazon TimestreamTime-series databaseIoT sensor data, telemetry, time-based metrics

How to Select the Right Database

Scenario LanguageCorrect ServiceReasoning
Graph queries / fraud detection / relationshipsAmazon NeptunePurpose-built for graph data
Data warehouse / petabyte analyticsAmazon RedshiftOptimized for analytical workloads
NoSQL / single-digit ms / millions of requestsAmazon DynamoDBServerless NoSQL with consistent low latency
In-memory / microsecond / cachingAmazon ElastiCacheIn-memory caching for performance
High availability for RDSMulti-AZ deploymentSynchronous standby with automatic failover
Read scaling for RDSRead ReplicasAsynchronous replication for read performance
Common Misconception: Multi-AZ vs Read Replicas

Multi-AZ provides high availability through a synchronous standby database with automatic failover. Read Replicas provide read scaling through asynchronous replication. These serve different purposes and are not interchangeable.

"High availability" or "automatic failover" points to Multi-AZ. "Read performance" or "read scaling" points to Read Replicas.

3.4 Networking Services

The exam tests whether you can select the appropriate networking service for a described connectivity or performance requirement.

RequirementServiceKey Characteristic
Dedicated private connection, no public internetAWS Direct ConnectPrivate physical network connection
Encrypted tunnel over public internetAWS Site-to-Site VPNQuick to set up, uses internet
Connect many VPCs in a hub-and-spoke topologyAWS Transit GatewayCentral hub for VPC connectivity
Cache content globally for lower latencyAmazon CloudFrontCDN with edge caching
Route live traffic over the AWS global networkAWS Global AcceleratorImproves performance for live traffic
HTTP/HTTPS load balancingApplication Load BalancerLayer 7, path-based routing
TCP/UDP extreme performanceNetwork Load BalancerLayer 4, high throughput
Key Distinction: CloudFront vs Global Accelerator

CloudFront caches content at edge locations to reduce latency for static and dynamic content. Global Accelerator routes live traffic over the AWS backbone to improve performance without caching. "Cache" points to CloudFront. "Route live" points to Global Accelerator.

3.5 Management and Monitoring Tools

Three AWS services are commonly confused. Each answers a different question.

ServicePrimary QuestionData Type
AWS CloudTrailWho did what and when?API activity logs
Amazon CloudWatchHow is performance trending?Metrics, logs, alarms
AWS ConfigWhat is the configuration state?Resource configuration history
Memory Aid

CloudTrail records API calls — the audit trail of actions. CloudWatch monitors performance metrics and logs. Config tracks resource configuration changes and evaluates compliance against desired settings.

3.6 AI, Machine Learning, and Analytics Services

The exam tests whether you can identify the correct AI/ML or analytics service for a described use case.

ServiceFunctionUse Case
Amazon SageMakerFull ML lifecycleBuild, train, and deploy machine learning models
Amazon BedrockFoundation models as APIGenerative AI without managing infrastructure
Amazon RekognitionImage and video analysisObject detection, facial analysis
Amazon TranscribeSpeech to textConvert audio to text transcripts
Amazon PollyText to speechConvert text to natural-sounding speech
Amazon TextractDocument text extractionExtract text and data from scanned documents
Amazon AthenaServerless SQL on S3Query data in S3 without ETL
AWS GlueServerless ETLPrepare and transform data for analytics
Amazon QuickSightBusiness intelligenceCreate dashboards and visualizations
Amazon KinesisReal-time streamingIngest and process streaming data
Common Pairs to Distinguish
  • Transcribe = speech to text. Polly = text to speech.
  • Rekognition = images and video. Textract = documents and forms.
  • Athena = SQL on S3. Glue = ETL. QuickSight = visualization.
Chapter 3 — Key Takeaways
  • Reserved Instances are for steady-state workloads. Spot is for interruptible workloads. On-Demand is for unpredictable workloads.
  • S3 Glacier Instant Retrieval provides real-time access without a restore request. Flexible and Deep Archive require restore operations.
  • Multi-AZ provides high availability for RDS. Read Replicas provide read scaling.
  • Direct Connect is a private connection. VPN is encrypted over the internet.
  • CloudTrail records WHO did WHAT. CloudWatch monitors performance. Config tracks configuration state.
  • Neptune = graph. Redshift = warehouse. DynamoDB = NoSQL. ElastiCache = in-memory cache.
⚡ Domain 3 Complete
34% of Your Exam Lives Here — Find Your Weak Spots

Technology & Services is the biggest domain at 34% of your score — about 22 questions. You've internalized the Decision Matrices and trigger words. But this is where AWS hides its craftiest distractors: Lambda vs Fargate, CloudFront vs Global Accelerator, Multi-AZ vs Read Replicas.

  • EC2 purchasing scenarios with realistic multi-option distractors
  • S3 storage class selection — including the retrieval options distinction
  • Database selection: Neptune, Redshift, DynamoDB, ElastiCache discrimination
  • Networking and AI/ML service identification under real exam conditions
Run the Domain 3 Readiness Check → Domain-filtered exam mode available · Pinpoint exactly where to focus your final hours.
CHAPTER 4
Billing, Pricing & Support
Domain 4 · 12% of Exam Score
Instructor's Note

This domain has the smallest exam weight but is highly predictable. The cost management tools and support plan tiers follow consistent patterns. Master these, and you can secure these points efficiently.

4.1 Cost Management Tools

Four AWS tools handle different aspects of cost management. Each operates in a different time frame or serves a different purpose.

ToolPurposeWhen to Use
AWS Pricing CalculatorEstimate costs before deploymentPlanning phase — "What will this cost?"
AWS Cost ExplorerAnalyze historical costs and usageReview phase — "What did we spend and why?"
AWS BudgetsSet spending limits and receive alertsOngoing — "Alert me when spending exceeds a threshold"
AWS Cost and Usage ReportMost granular line-item billing dataDetailed analysis — "I need raw data for chargeback"
Scenario LanguageCorrect ToolReasoning
Estimate before deploymentPricing CalculatorFuture costs = Pricing Calculator
Visualize past spending trendsCost ExplorerPast analysis = Cost Explorer
Alert when spending exceeds thresholdAWS BudgetsLimits and alerts = Budgets
Granular line-item data for chargebackCost and Usage ReportRaw detail = CUR

4.2 AWS Support Plans

AWS offers multiple support plans. The exam tests whether you can identify which plan provides a specific feature.

Important Update: Support Plan Changes in 2026–2027

AWS has announced significant changes to its support plans:

  • Developer Support will be discontinued on January 1, 2027. Customers can continue using their existing plan or upgrade to Business Support+ before that date.
  • Enterprise On-Ramp will be discontinued on January 1, 2027. Throughout 2026, Enterprise On-Ramp customers will be automatically upgraded to Enterprise Support during contract renewal. The upgraded Enterprise Support includes a designated TAM, 15-minute response times, and a lower $5,000 minimum (reduced from $15,000).
  • Business Support+ is the current name for the Business tier, offering AI-powered support and 24/7 access to AWS engineers.
  • These changes apply to commercial AWS Regions only. Developer Support, Business Support, and Enterprise On-Ramp remain available in AWS GovCloud (US).

Exam guidance: For current CLF-C02 exam versions, Enterprise On-Ramp remains a valid answer for TAM-related questions. Be aware that future exam versions may reflect the discontinuation.

PlanMinimum Monthly CostKey Features
BasicFreeAccount and billing support, service quota increases, documentation
Developer$29 or 3% of monthly usage (whichever is greater)Email support during business hours. End of support: January 1, 2027
Business Support+$100 or tiered percentage (10%/7%/5%/3%) (whichever is greater)24/7 phone, chat, and web. Full Trusted Advisor access.
Enterprise On-Ramp$5,500 minimumPool of TAMs, Concierge support. End of support: January 1, 2027
Enterprise$15,000 minimum (may be reduced to $5,000 for upgraded On-Ramp customers)Designated TAM, 15-minute response for business-critical, Security Incident Response
Unified Operations$50,000+Domain Specialist Engineers, AWS Countdown Premium, proactive incident management. New highest tier.

How to Select the Right Support Plan

Scenario LanguageCorrect PlanReasoning
Full Trusted Advisor at lowest costBusiness Support+Full TA access requires Business tier or higher
Designated Technical Account Manager (TAM)EnterpriseDesignated TAM is Enterprise-only
24/7 phone support at lowest costBusiness Support+24/7 phone access begins at Business tier
Access to Shield Response Team (SRT)AWS Shield Advanced + Business Support+SRT is NOT a support plan feature; it requires Shield Advanced and Business Support or higher
Common Misconception: SRT and Support Plans

Access to the Shield Response Team (SRT) is not included in any AWS Support plan alone. SRT access requires AWS Shield Advanced combined with Business Support or higher. This distinction appears in exam questions that describe DDoS response requirements.

4.3 AWS Organizations and Control Tower

These services help manage multiple AWS accounts, but they serve different purposes.

ServicePrimary PurposeKey Capability
AWS OrganizationsCentralized management of multiple accountsConsolidated billing, Service Control Policies (SCPs)
AWS Control TowerSet up and govern a multi-account environmentAutomated account provisioning with guardrails
Key Distinction

AWS Organizations provides consolidated billing and policy-based controls (SCPs). Control Tower sets up a governed multi-account environment with best-practice configurations.

4.4 Reserved Instance Rules

Reserved Instances offer significant discounts in exchange for commitment. The exam may test whether you understand the difference between Standard and Convertible RIs.

RI TypeDiscount LevelFlexibilitySellable on Marketplace?
Standard RIHigher discount (up to 72%)Fixed instance familyYes — RI Marketplace
Convertible RILower discountCan change instance familyNo
Savings PlansUp to 72%Applies across EC2, Lambda, FargateN/A

Scenario Practice

ScenarioCorrect AnswerReasoning
Finance wants automatic alerts when monthly spend exceeds $10,000.AWS BudgetsThreshold-based alerts = Budgets
Architect needs to estimate costs before deploying 100 EC2 instances.AWS Pricing CalculatorPre-deployment estimation = Pricing Calculator
Company needs one invoice for eight AWS accounts with shared discounts.AWS OrganizationsConsolidated billing = Organizations
Chapter 4 — Key Takeaways
  • Pricing Calculator = future estimates. Cost Explorer = past analysis. Budgets = limits and alerts. CUR = raw detailed data.
  • Business Support+ is the lowest tier with full Trusted Advisor access.
  • Designated TAM requires Enterprise Support. SRT requires Shield Advanced + Business Support or higher.
  • Organizations provides consolidated billing and SCPs. Control Tower sets up governed multi-account environments.
  • Standard RIs are sellable on the RI Marketplace. Convertible RIs are not.
  • Developer Support and Enterprise On-Ramp have announced end-of-support dates in 2027.
⚡ Domain 4 Complete
Highest-ROI Domain Done — Now Secure Those Points

Eight questions. Four cost tools. Six support tiers. If the patterns clicked as you read, Domain 4 should feel like free points. But "felt clear while reading" and "fires correctly in 83 seconds under exam pressure" are two different things.

  • Pricing Calculator vs Cost Explorer vs Budgets — same-question distractor drills
  • Support plan tier questions with SRT / TAM / Full TA precision
  • Organizations vs Control Tower scenario discrimination
  • Reserved Instance rules: Standard vs Convertible vs Savings Plans
Lock In Your Domain 4 Score → Pass on your first attempt · 6 months access · No subscription, no games.
CHAPTER 5
The Elimination Playbook
You don't need the right answer — you need to eliminate three wrong ones
Instructor's Note

You don't need to know the right answer to eliminate three wrong ones. AWS builds its wrong answers with tells — phrases that reveal they're incorrect before you've even finished reading them. This chapter trains you to see those tells automatically.

5.1 High-Confidence Eliminators

Every phrase below is almost always wrong. The moment you see one, you can eliminate the answer without reading further.

"Contact AWS Support to configure..."
AWS never requires support contact for configuration tasks — you do it yourself in the console.
"Manually patch the RDS database OS"
RDS is managed — AWS owns the OS entirely. Customer never touches it.
"GuardDuty automatically blocks the traffic"
GuardDuty DETECTS only — zero blocking capability. WAF blocks HTTP. Shield blocks DDoS.
"Install a monitoring agent on Lambda"
Lambda is serverless — there is no server to install anything on.
"S3 Glacier for real-time access"
Glacier is an archive tier. Real-time access requires S3 Standard or Glacier Instant Retrieval (no restore request).
"Reserved Instances for unpredictable loads"
RIs need a commitment. Unpredictable workloads should use On-Demand.
"Lambda for a 4-hour batch job"
Lambda synchronous invocations are limited to 15 minutes. A 4-hour job eliminates this answer immediately.
"CloudWatch to find who deleted X"
WHO = CloudTrail. CloudWatch only tracks metrics and logs, not API activity.
"SRT via Enterprise Support alone"
SRT requires Shield Advanced combined with Business Support or higher. Not a support plan feature by itself.
"AWS owns the security group config"
Security group rules = Customer always. No exceptions.

5.2 Managed Service Elimination Rules

For any managed service (RDS, Lambda, DynamoDB, Fargate) — if the answer says the customer must do any of the following, eliminate it immediately:

If the Answer Says Customer Must...Reality Check
Patch the operating systemRDS, Lambda — AWS owns and patches the OS. You never touch it.
Manage automated backupsAmazon RDS — AWS automates the backup mechanism. Customer configures retention period.
Configure server capacityLambda, Fargate — Serverless = AWS manages this.
Replace failed hardwareAll managed services — AWS handles all hardware.
Monitor the hypervisorEC2, RDS — Virtualization layer = AWS. Always.

5.3 Most Confused Service Pairs

PairHow to Separate Them
CloudTrail vs CloudWatchTrail = WHO did WHAT (audit). Watch = WHAT metrics (performance). Completely different questions.
Shield vs WAF'DDoS/flood' = Shield. 'SQL injection/XSS/bots' = WAF. Different threat layers.
Inspector vs GuardDutyInspector = proactive SCAN. GuardDuty = continuous DETECT.
Multi-AZ vs Read Replicas'High availability/failover' = Multi-AZ. 'Read scaling' = Read Replicas. NEVER swap.
Secrets Manager vs Parameter StoreAuto-rotation for RDS = Secrets Manager. Basic storage = Parameter Store.
CloudFront vs Global AcceleratorCloudFront = CDN CACHE. Global Accelerator = live ROUTE.
Cognito vs IAM Identity CenterCognito = app CUSTOMERS. Identity Center = EMPLOYEES.
CHAPTER 6
Night Before: Rhythmic Memory Anchors
Stop new material. Lock in what you know.
Instructor's Protocol

Stop all new material 12 hours before the exam. No new services. No new concepts. What you don't know tonight, you won't know in the exam room. Read every anchor below OUT LOUD. The rhythm is engineered for spoken recall.

The Rhythmic Anchors — Speak Them, Don't Just Read Them

🔍
WHO = CloudTrail. WHAT performance = CloudWatch. WHAT config = AWS Config. CloudTrail management events on by default for 90 days. Data events off by default.
↕️
If it goes UP and DOWN automatically — Elasticity. If it only GROWS — Scalability. Bidirectional + automatic = elasticity only.
🔄
If it RECOVERS — Reliability Pillar. If it IMPROVES PROCESSES — Operational Excellence. RECOVER → Reliability. IMPROVE → OE.
🧊
Glacier Instant Retrieval: Millisecond access, no restore required, quarterly access pattern. Glacier Flexible Retrieval: Requires restore. Expedited = 1–5 min; Standard = 3–5 hours; Bulk = 5–12 hours. Glacier Deep Archive: Standard = 12 hours; Bulk = 48 hours. Instant = no restore. Flexible and Deep Archive = restore required.
🏠
Customer CLICKS it in the console — Customer's job. In the DATA CENTER — AWS's job. The Shared Responsibility shortcut.
🛡️
DETECTS threats — GuardDuty. SCANS vulnerabilities — Inspector. BLOCKS HTTP attacks — WAF. BLOCKS DDoS — Shield. Three verbs. Four services. Never overlap.
💼
SRT — Shield Advanced + Business Support+. TAM — Enterprise Support. Full Trusted Advisor — Business Support+. Three questions. Three different answers.
🌐
CACHES static content at edge — CloudFront. ROUTES live traffic via AWS backbone — Global Accelerator. Cache = CloudFront. Route = Global Accelerator.
⚡
CODE without servers — Lambda. CONTAINERS without servers — Fargate. Lambda = code. Fargate = containers.
🗄️
Graph queries — Neptune. Data warehouse — Redshift. NoSQL at scale — DynamoDB. Three database triggers. Three different answers.
🔑
Auto-rotates DB credentials — Secrets Manager. Stores a config value — Parameter Store. Auto-rotation for RDS = Secrets Manager only.
🎙️
Speech going IN — Transcribe. Speech coming OUT — Polly. Audio→text = Transcribe. Text→audio = Polly. Mirror images.
💰
Estimates FUTURE costs — Pricing Calculator. Analyzes PAST costs — Cost Explorer. Sets an ALERT — Budgets. Three tools. Three time frames.
📋
Compliance REPORTS — Artifact. Compliance CHECKS on resources — Config. PDF docs = Artifact. Resource rules = Config.

Exam-Day Protocol

TimeAction
T-12 hrsStop all new material. Read anchors aloud once. Sleep early.
T-2 hrsRead the Morning-Of Checklist (Bonus 3). Anchors once more.
T-0Read every question stem fully. Classify type before reading choices.
StuckApply High-Confidence Eliminators. Flag and move. Never stall on one question.
ReviewNever change answers without a specific, concrete reason.
MODULE A
Top 50 Exam Traps Library
50 traps · Distinction logic · Extracted from real CLF-C02 questions
Instructor's Note

Format: Trap → Why It's Tempting → How to Distinguish. For each trap, ask yourself: "Would I have fallen for that?" If the answer is yes — that's your personal study target. Candidates who fall into these traps lose an average of 8–12 points.

T01 [D1]
Elasticity vs Scalability
Why It's Tempting
Both involve handling load — candidates swap them constantly.
How to Distinguish
Elasticity = auto UP+DOWN. Scalability = growth only. 'Release' = elasticity every time.
T02 [D1]
Economies of Scale vs No Upfront Costs
Why It's Tempting
Both sound like cost savings — AWS puts both as choices in the same question.
How to Distinguish
Economies of scale = lowers VARIABLE costs. Trade fixed for variable = eliminates CapEx.
T03 [D1]
'Test recovery' → Operational Excellence
Why It's Tempting
Sounds operational — but it's Reliability.
How to Distinguish
RECOVER = Reliability. IMPROVE = OE. One word is the whole answer.
T08 [D2]
RDS OS patching = Customer
Why It's Tempting
EC2 guest OS patching IS customer — candidates extend that logic to RDS.
How to Distinguish
RDS is a managed service. AWS owns and patches the RDS OS. Customer never touches it.
T10 [D2]
GuardDuty blocks attacks
Why It's Tempting
'GuardDuty protects' sounds like blocking.
How to Distinguish
GuardDuty DETECTS and ALERTS only. WAF blocks. Shield blocks. GuardDuty does not.
T19 [D3]
Lambda for 4-hour batch jobs
Why It's Tempting
Lambda is serverless — candidates default to it.
How to Distinguish
Lambda sync = 15-minute limit. 4 hours = Fargate or AWS Batch.
T20 [D3]
Read Replicas for high availability
Why It's Tempting
More copies = availability in candidates' minds.
How to Distinguish
Multi-AZ = SYNCHRONOUS standby + auto failover = HA. Read Replicas = async = PERFORMANCE.
T36 [D4]
Pricing Calculator vs Cost Explorer
Why It's Tempting
Both deal with costs — candidates conflate them.
How to Distinguish
Pricing Calculator = BEFORE deployment (future). Cost Explorer = AFTER (past).
T38 [D4]
SRT via Enterprise Support
Why It's Tempting
Enterprise is the highest tier — candidates assume it includes SRT.
How to Distinguish
SRT requires Shield ADVANCED + Business Support or higher. Enterprise Support alone does not include SRT.
MODULE B
100 Must-Know Trigger Words
Read a trigger phrase. Say the answer out loud. That's the level.
Instructor's Note

These 100 trigger phrases appear in CLF-C02 question stems. Cover the Answer column. Read a trigger phrase. Say the answer out loud before your eyes reach it. That's the level of automaticity you need.

#Trigger PhraseAnswerWhy
1who deleted / modified / created resourceAWS CloudTrailWHO = CloudTrail always
2API call audit / historyAWS CloudTrailAudit = CloudTrail
3CPU metrics / performance alarmsAmazon CloudWatchMetrics = CloudWatch
4configuration compliance / drift detectionAWS ConfigConfig state = AWS Config
5compliance report / SOC / PCI / ISOAWS ArtifactReports = Artifact
6best-practice recommendationsAWS Trusted AdvisorRecs = Trusted Advisor
7threat detection / malicious activityAmazon GuardDutyActive threat = GuardDuty
8vulnerability scan / CVE assessmentAmazon InspectorCVE = Inspector
9sensitive data in S3 / PII / PHIAmazon MacieS3 data = Macie
10DDoS protection / flood attackAWS ShieldDDoS = Shield
11SRT / Shield Response TeamAWS Shield Advanced + Business Support+SRT requires both Shield Advanced and Business Support or higher
12SQL injection / XSS / bots / geo-blockAWS WAFHTTP attacks = WAF (when configured with rules)
13auto-rotate DB credentials / passwordsAWS Secrets ManagerAuto-rotation = Secrets Manager
14workforce SSO / multiple AWS accountsAWS IAM Identity CenterEmployee SSO = Identity Center
15app user sign-up / sign-inAmazon CognitoApp customers = Cognito
16serverless functions / event-drivenAWS LambdaServerless code = Lambda
17serverless containers / no clustersAWS FargateServerless containers = Fargate
18spot / cheapest / tolerates interruptionEC2 Spot InstancesCheapest + interruptible = Spot
19unknown access patterns / auto-tierS3 Intelligent-TieringAuto-tiering: 30d→IA, 90d→Archive Instant. Objects <128KB remain Frequent.
20rare + immediate / millisecond archiveGlacier Instant RetrievalNo restore required. Millisecond access for quarterly data.
21graph queries / fraud / relationshipsAmazon NeptuneGraph = Neptune
22data warehouse / petabyte analyticsAmazon RedshiftWarehouse = Redshift
23NoSQL / single-digit ms / serverless DBAmazon DynamoDBServerless NoSQL = DynamoDB
24in-memory / microsecond / Redis cacheAmazon ElastiCacheMicrosecond cache = ElastiCache
25no public internet / dedicated linkAWS Direct Connect'No public internet' = Direct Connect
26cache content globally / CDNAmazon CloudFrontCDN cache = CloudFront
27route live traffic / AWS backboneAWS Global AcceleratorLive routing = Accelerator
28infrastructure as code / IaC templatesAWS CloudFormationIaC = CloudFormation
29estimate before building / migrationAWS Pricing CalculatorBEFORE = Pricing Calculator
30analyze past costs / visualize spendAWS Cost ExplorerPAST = Cost Explorer
31set budget limit / alert thresholdAWS BudgetsLimit + alert + budget actions = Budgets.
32consolidated billing / single invoiceAWS OrganizationsOne invoice = Organizations
33TAM / Technical Account ManagerEnterprise SupportTAM = Enterprise tier
34full Trusted Advisor / all TA checksBusiness Support+ (min)Full TA = Business Support+ min. Basic/Developer = Service Limits + 6 selected checks.
35speech to text / transcribe audioAmazon TranscribeSpeech→text = Transcribe
36text to speech / voice outputAmazon PollyText→speech = Polly
37foundation models / GenAI / LLM APIAmazon BedrockGenAI API = Bedrock
38on-premises + same AWS APIsAWS OutpostsOn-prem AWS = Outposts
39recover automatically from failureReliability PillarAuto-recover = Reliability
40carbon footprint / minimize wasteSustainability PillarEnvironmental = Sustainability
MODULE C
24-Hour Emergency Cram Sheet
Stop studying. Read this. Read it again. Sleep. Execute.
Instructor's Protocol

This is your emergency protocol. 24 hours left. Do not open any other section. Do not search YouTube. Do not start a new course. Read this page. Read it again. Read the anchors out loud. Sleep. Execute.

Domain 1 — Cloud Concepts (24%)

  • 6 Benefits: Trade fixed→variable | Economies of scale | Stop guessing capacity | Speed+agility | Stop data center spending | Go global in minutes
  • Elasticity=auto UP+DOWN | Scalability=growth only | Reliability=RECOVER | Durability=data persists
  • 6 Pillars: OE=improve | Security=trace+protect | Reliability=recover | Performance=serverless | Cost=spend analysis | Sustainability=carbon
  • Multi-AZ=HA within region | Multi-Region=geographic disaster resilience
  • 7 Rs: Rehost=as-is | Replatform=managed+no code | Refactor=microservices | Repurchase=SaaS | Retire | Retain | Relocate=VMware

Domain 2 — Security & Compliance (30%)

  • AWS owns: hardware, hypervisor, managed service OS, automated RDS backups, Lambda runtime
  • Customer owns: IAM, EC2 guest OS, data, security groups, S3 policies, encryption config
  • GuardDuty=DETECTS (no block) | Inspector=SCANS CVEs | Macie=PII in S3 | WAF=blocks HTTP | Shield=blocks DDoS
  • CloudTrail=WHO did WHAT | CloudWatch=WHAT metrics | Config=WHAT config state
  • Security Group=stateful+instance | Network ACL=stateless+subnet | SRT=Shield Advanced + Business Support+

Domain 3 — Technology & Services (34%)

  • EC2: Spot=cheapest/interruptible | Reserved 3yr All Upfront=max savings | On-Demand=no commitment | Savings Plans=flexible
  • Lambda=15min sync; 90min async on Managed Instances | Fargate=serverless containers | Beanstalk=PaaS web
  • S3 Glacier retrieval: Instant=millisecond, no restore, quarterly access | Flexible=Expedited 1–5 min, Standard 3–5 hr, Bulk 5–12 hr | Deep Archive=Standard 12 hr, Bulk 48 hr, no expedited
  • Neptune=graph | Redshift=warehouse | DynamoDB=NoSQL | ElastiCache=in-memory | Multi-AZ=HA | Read Replicas=performance
  • Direct Connect=no internet+weeks | VPN=encrypted internet+hours | Transit Gateway=hub-and-spoke
  • CloudFront=CDN | Global Accelerator=backbone | CloudFormation=IaC
  • Transcribe=speech→text | Polly=text→speech | Athena=SQL on S3 | Glue=ETL | QuickSight=BI

Domain 4 — Billing & Pricing (12%)

  • Pricing Calculator=FUTURE estimate | Cost Explorer=PAST analysis | Budgets=LIMITS+ALERTS | CUR=raw granular data
  • Support (2026): Basic=free | Developer=$29 or 3% (EOS Jan 1, 2027) | Business Support+=$100 or tiered (full TA) | Enterprise On-Ramp=$5,500 (EOS Jan 1, 2027) | Enterprise=$15k min (reduced to $5k for upgraded On-Ramp customers) | Unified Operations=$50k+ (new top tier).
  • Full TA=Business Support+ minimum | SRT=Shield Advanced + Business Support+ | TAM=Enterprise
  • Organizations=consolidated billing+SCPs | Control Tower=multi-account governance setup
⛔ Common Elimination Patterns
  • ✕ 'GuardDuty automatically blocks' → GuardDuty never blocks
  • ✕ 'Manually patch RDS OS' → AWS owns RDS OS
  • ✕ 'Lambda for 4-hour job' → Lambda sync max = 15 min
  • ✕ 'CloudWatch to find who deleted X' → WHO = CloudTrail
  • ✕ 'SRT via Enterprise Support alone' → SRT requires Shield Advanced + Business Support+
  • ✕ 'Reserved Instances for unpredictable workloads' → RIs need commitment
  • ✕ 'S3 Glacier for real-time access' → Glacier = archive

Rhythmic Anchors — Say These Out Loud

🔍
WHO=CloudTrail | WHAT metrics=CloudWatch | WHAT config=Config
🔄
RECOVER=Reliability | IMPROVE=Operational Excellence
🧊
INSTANT=no restore | FLEXIBLE=3–5 hr standard | DEEP ARCHIVE=12 hr standard
🛡️
DETECT=GuardDuty | SCAN=Inspector | BLOCK HTTP=WAF | BLOCK DDoS=Shield
💼
SRT=Shield Advanced + Business Support+ | TAM=Enterprise | Full TA=Business Support+
🌐
Cache=CloudFront | Route live=Global Accelerator
BONUS 1
How AWS Writes Trick Questions
The techniques — once you see them, you can't unsee them
Instructor's Note

AWS is not just testing your knowledge of AWS. It is testing your ability to read precisely. Every technique below is a mechanism designed to make you pick the answer you recognize rather than the answer that's correct.

Technique 1 — The Distractor Answer

AWS places one answer that is technically correct in isolation — but wrong for the specific scenario.

⚠ Example

"A company needs to recover its RDS database automatically during a failure. Which feature provides this?"

  • A: Read Replicas ✗ — real RDS feature, but wrong purpose
  • B: Multi-AZ deployment ✓ — automatic failover = Multi-AZ's entire purpose
Tip

Always read the scenario trigger word BEFORE scanning answers. 'Automatically recover' locks you to Multi-AZ before you've even seen the options.

Technique 2 — The Partial Correctness Trap

Two answer choices are partially correct. One addresses the scenario completely. One addresses only part of it.

Technique 3 — The Keyword Swap

AWS places a service that is 99% correct for a related scenario — but wrong for the exact scenario due to one swapped capability:

  • GuardDuty vs Inspector (detect vs scan)
  • CloudFront vs Global Accelerator (cache vs route)
  • Multi-AZ vs Read Replicas (HA vs read performance)

Technique 4 — The Managed Service Responsibility Trap

The Managed Service Rule
  • Customer owns: data, access control, configuration choices
  • AWS owns: OS, patching, backup mechanism, hardware, hypervisor

The boundary shifts depending on whether the service is managed. RDS? AWS patches the OS. EC2? You patch the OS.

Technique 5 — The Scope Mismatch

  • VPC Peering connects VPCs — but point-to-point. Many VPCs = Transit Gateway.
  • EBS is block storage — single-instance only. Multi-instance = EFS.
  • Security Groups work — at instance level only. Subnet = NACL.
BONUS 2
The 80/20 of CLF-C02
Where your study time actually goes
Instructor's Note

Tier 1 concepts are heavily tested. Tier 2 appears occasionally. Tier 3 appears rarely.

Note: The specific claim that Tier 1 concepts appear in a set number of questions per exam is not published by AWS. This tier list reflects commonly tested concepts based on exam guide alignment, not official per-concept question counts.

Tier 1 — Must Master First (60% of study time)

Concept / ServiceDomainWhy It's Critical
Shared Responsibility ModelD2Direct questions + embedded in other questions as context
IAM — Users / Roles / GroupsD2Appears in compute, storage, security, and architecture questions
EC2 Purchasing OptionsD3Reserved vs Spot vs On-Demand appears multiple times per exam
AWS CloudTrailD2/D3'WHO' questions — the most common single-service question type
Well-Architected 6 PillarsD1Direct pillar questions every exam + architecture scenario context
S3 Storage ClassesD3Storage class selection — highly predictable
The 4 Cost Management ToolsD4Pricing Calculator / Explorer / Budgets / CUR
The Support Plan TiersD4Trusted Advisor + TAM + SRT questions
Security Service MapD2GuardDuty/Inspector/WAF/Shield/Macie
BONUS 3
The Morning-Of Checklist
Pre-flight protocol. Nothing gets skipped.
Instructor's Note

You have done the work. This checklist is not about cramming — it's about removing friction so your preparation can perform. Execute this like a pre-flight checklist. Nothing gets skipped.

#ItemWhat to Do
1Verify Exam Slot & Time ZoneLog into Pearson VUE. Confirm exact start time in YOUR local time zone.
2Prepare Government-Issued IDTwo forms of ID ready if testing online.
3Test Webcam & MicrophoneRun Pearson VUE's system test at least 30 minutes before your exam.
4Close All Background ApplicationsClose everything: Slack, email, browser tabs.
5Check Internet ConnectionUse wired ethernet if possible. Run a speed test.
6Clear Your WorkspaceDesk clear: no papers, no notes, no second monitors, no books.
7Hydrate & Eat a Real MealEat a balanced meal 60–90 minutes before the exam.
8Trust Your SleepSleep consolidates memory. 7+ hours = better recall than last-minute cramming.
9Read Rhythmic Anchors Once MoreOpen Chapter 6. Read the anchor pairs out loud once. Takes 4 minutes.
10Set Pace & Breathe90 minutes / 65 questions = 83 seconds per question. Flag stuck questions and move forward.
You’ve Read the Playbook.
Now Simulate the Exam.

Every pattern in this guide has a corresponding question waiting to test it. Confirming you’re truly ready means facing CLF-C02-style pressure before the real thing — on your schedule, with instant feedback.


  • 390+ realistic questions built to match CLF-C02’s question style and trap patterns
  • 6 full 65-question exams — simulate complete exam sessions with real time pressure
  • Domain-targeted filters — drill Cloud Concepts, Security, Technology, or Billing independently
  • Explanations for every answer, written in the same instructor voice as this guide
  • 6 months of unlimited access — one-time $29.99 per certification, no subscription
Unlock the CLF-C02 Premium Simulator →

Designed exclusively for CLF-C02 · Pass on your first attempt.

BONUS 4
AWS Acronym Cheat Sheet
Confusing acronyms cost you time — eliminate that friction now
Instructor's Note

Run through this once — you'll be surprised how many you already know, and how quickly the gaps fill in.

AcronymFull NameOne-Line Meaning
IAMIdentity and Access ManagementManage WHO can do WHAT on AWS resources
MFAMulti-Factor AuthenticationSecond verification layer
STSSecurity Token ServiceIssues temporary credentials for roles and federation
SCPService Control PolicyGovernance guardrail restricting what accounts can do in Organizations
VPCVirtual Private CloudYour logically isolated network inside AWS
NACLNetwork Access Control ListStateless subnet-level firewall
SGSecurity GroupStateful instance-level firewall
IGWInternet GatewayEnables two-way internet access for public VPC subnets
NATNetwork Address TranslationAllows private subnets to reach internet outbound only
EC2Elastic Compute CloudVirtual server instances in the cloud
EBSElastic Block StoreBlock storage attached to a single EC2 instance
EFSElastic File SystemManaged NFS shared file system for multiple EC2 instances
S3Simple Storage ServiceScalable object storage
RDSRelational Database ServiceManaged SQL database
ALBApplication Load BalancerLayer 7 HTTP/HTTPS load balancer with path-based routing
NLBNetwork Load BalancerLayer 4 TCP/UDP load balancer for extreme performance
KMSKey Management ServiceCreate and manage encryption keys for AWS services
WAFWeb Application FirewallFilter HTTP/HTTPS traffic — block SQL injection, XSS, bots (when configured)
IaCInfrastructure as CodeProvision infrastructure via code/templates
CAFCloud Adoption FrameworkAWS framework with 6 perspectives for planning cloud migration
RIReserved Instance1–3 year EC2 commitment for up to 72% discount
SRTShield Response TeamAvailable only via Shield Advanced + Business Support or higher
TAMTechnical Account ManagerDesignated AWS advisor — Enterprise Support only
AZAvailability ZoneIsolated data center within a Region
ETLExtract, Transform, LoadData pipeline process — AWS Glue is the managed ETL service
MLMachine LearningAI models that learn from data — SageMaker is AWS's full ML platform
LLMLarge Language ModelFoundation model for GenAI — Amazon Bedrock
© 2026 CloudExamPro.com · Premium Edition · Do not distribute or reproduce without permission.
AWS, Amazon Web Services, and all related service names are trademarks of Amazon.com, Inc.
This guide is an independent exam preparation product and is not affiliated with or endorsed by AWS.
Last technically reviewed: October 2026
Limited-time offer · ends in --Days:--Hrs:--Min:--Sec
Get Instant Access