CLF-C02 Premium
Strategy Guide
Pattern recognition. Decision matrices. Zero wasted study time.
The surgical playbook for CLF-C02 — decoded and structured for your use.
This Is Not a Textbook
This guide is built around one objective: help you earn the certification quickly, cleanly, and on your first attempt. That means no filler, no AWS encyclopedia, and no walls of text about infrastructure you'll never touch. Instead, you get the patterns that appear on this exam, decoded into decision rules you can apply in the exam chair.
Many capable people fail this exam not because they don't know AWS, but because they don't know how AWS writes the questions. This guide teaches you to read the scenarios the way the exam intends.
What Makes This Different
| Feature | Standard Guides | This Guide |
|---|---|---|
| Approach | Teach AWS theory | Train exam pattern recognition |
| Traps | Rarely mentioned | 50 traps catalogued with distinction logic |
| Memory | Bullet lists | Rhythmic anchor cadence — spoken recall |
| Decisions | Paragraphs | 16 Decision Matrices — one-word triggers |
| Last Day | Review notes | 24-Hour Cram Sheet — ultra-condensed |
The Exam in 60 Seconds
- 65 questions · 90 minutes — Passing score: approximately 700/1000
- 4 domains: Cloud Concepts 24% | Security 30% | Technology 34% | Billing 12%
- Approximately 83 seconds per question — pattern recognition reduces this significantly
- Some questions are unscored pilot questions — answer every one as if it counts
Your 14-Day Study Plan
| Days | Focus | Priority |
|---|---|---|
| Days 1–3 | Chapters 1 + 4 — 36% of exam | Fastest return on study time |
| Days 4–7 | Chapter 2 — Security (30%) | The domain that rewards pattern work most |
| Days 8–11 | Chapter 3 — Technology (34%) | Use Decision Matrices every session |
| Day 12 | Chapter 5 — Elimination Playbook | Rehearse high-confidence eliminators |
| Day 13 | Chapter 6 + Module C | Rhythmic Anchors aloud + Cram Sheet review |
| Day 14 | EXAM DAY — Bonus 3 Morning-Of Checklist | Execute |
Cloud Concepts is often underestimated because it sounds conceptual. In practice, AWS embeds precise vocabulary into scenario questions, and small distinctions — like the difference between elasticity and scalability — determine whether an answer is correct. This chapter builds the vocabulary foundation you will rely on across all four domains.
1.1 The Six Advantages of Cloud Computing
AWS defines six core benefits. Two of them — economies of scale and trading fixed costs for variable costs — sound similar but describe different financial mechanisms.
| Benefit | What It Means | How AWS Tests It |
|---|---|---|
| Trade fixed expense for variable expense | Replace upfront capital expenditure (CapEx) with pay-as-you-go operational expenditure (OpEx). | Scenarios mentioning no upfront investment or CapEx reduction |
| Benefit from massive economies of scale | AWS purchases hardware in aggregate volume, reducing variable costs for customers. | Scenarios mentioning lower variable costs or bulk purchasing |
| Stop guessing capacity | Provision resources based on actual demand rather than forecasts. No idle servers. | Scenarios mentioning over-provisioning or right-sizing |
| Increase speed and agility | Launch resources in minutes instead of weeks. Faster experimentation and time-to-market. | Scenarios mentioning rapid deployment or faster innovation |
| Stop spending on data centers | Focus on your product rather than managing physical infrastructure. | Scenarios mentioning undifferentiated heavy lifting |
| Go global in minutes | Deploy applications across multiple geographic Regions quickly. | Scenarios mentioning global reach or low-latency deployment |
Economies of scale does not mean "eliminates upfront costs." That describes trading fixed for variable.
- Economies of scale = AWS's aggregate purchasing power lowers your variable costs.
- Trade fixed for variable = You replace CapEx with OpEx. No large upfront purchase.
AWS places both as answer choices in the same question. They are distinct concepts.
1.2 Core Vocabulary: Elasticity, Scalability, Reliability, Durability
These four terms appear frequently and are commonly confused. Each describes a different system characteristic.
| Term | Precise Definition | Key Distinction |
|---|---|---|
| Elasticity | Automatically provision and release resources based on demand. Bidirectional and automatic. | Automatically scales in AND out |
| Scalability | Ability to grow to handle increased demand. One-directional growth. | Grows to meet demand |
| Reliability | Automatically recover from failure and consistently meet performance expectations. | Recovers from failure |
| Durability | Long-term data persistence. Data does not disappear or become corrupted. | Data persists over time |
How to Distinguish Them in Scenarios
| Scenario Language | Correct Answer | Reasoning |
|---|---|---|
| Automatically provision AND release capacity | Elasticity | Bidirectional and automatic |
| Grow to handle increasing traffic | Scalability | Growth without automatic release |
| Recover from failure consistently | Reliability | Recovery is the key attribute |
| Data persists with 11 nines of durability | Durability | Data survival, not system recovery |
1.3 AWS Well-Architected Framework — Six Pillars
The Well-Architected Framework provides design principles for building on AWS. The exam tests whether you can map a design goal to the correct pillar.
| Pillar | Design Focus | Scenario Trigger |
|---|---|---|
| Operational Excellence | Run and monitor systems to deliver business value. Continuously improve processes. | Improve processes / automate operations |
| Security | Protect information, systems, and assets. Enable traceability. Apply least privilege. | Protect data / traceability / least privilege |
| Reliability | Ensure a system performs its intended function correctly and consistently. Recover from failure. | Recover from failure / test recovery |
| Performance Efficiency | Use computing resources efficiently. Adopt serverless where appropriate. | Serverless / right resource type |
| Cost Optimization | Avoid unnecessary costs. Analyze spending and eliminate waste. | Analyze spend / reduce cost |
| Sustainability | Minimize environmental impact of cloud workloads. | Carbon footprint / environmental impact |
"Test recovery procedures" sounds like an operational activity, but it belongs to the Reliability pillar. The Reliability pillar's design principle is "Automatically recover from failure," and testing recovery is part of that principle.
"Continuously improve processes" belongs to Operational Excellence.
These two are the most frequently swapped pillar concepts in exam questions.
1.4 AWS Global Infrastructure
AWS's global infrastructure consists of three nested layers, each serving a distinct purpose.
| Component | Description | Typical Count |
|---|---|---|
| Region | Geographic area containing multiple, isolated Availability Zones. | 30+ globally |
| Availability Zone (AZ) | One or more discrete data centers with redundant power, networking, and connectivity. | 2–6 per Region |
| Edge Locations | Sites used by CloudFront and Route 53 to cache content closer to users. | Hundreds globally |
- Multi-AZ deployment provides high availability within a Region. AZs have independent power and networking.
- Multi-Region deployment provides geographic fault tolerance for disasters affecting an entire Region.
- Edge Locations are more numerous than AZs, which are more numerous than Regions.
If a scenario mentions "natural disaster" or "geographic redundancy," the correct answer is multiple Regions.
Availability Zones are isolated from each other for local failures, but they share the same geographic area. A regional disaster affects all AZs in that Region.
1.5 AWS Cloud Adoption Framework (CAF) — Six Perspectives
The AWS CAF provides guidance for organizations planning cloud adoption. The exam tests whether you can identify which perspective addresses a given concern.
| Perspective | Focus Area | Scenario Trigger |
|---|---|---|
| Business | Business value, ROI, strategic alignment | Executive buy-in, business case |
| People | Organizational change, skills, culture | Team training, agile adoption |
| Governance | Risk management, portfolio, data governance | Compliance, risk controls |
| Platform | Cloud architecture, infrastructure as code | Architecture standards, IaC |
| Security | Identity, detection, protection, response | IAM at scale, threat detection |
| Operations | Day-to-day operations, event management | Operational processes, monitoring |
1.6 Migration Strategies — The Seven Rs
When organizations migrate workloads to AWS, they choose from seven common strategies. The exam tests whether you can identify which strategy matches a described approach.
| Strategy | Description | Scenario Trigger |
|---|---|---|
| Rehost (Lift and Shift) | Move applications as-is to AWS without changes. | As-is / no changes |
| Replatform | Make limited optimizations without changing core architecture. | Optimize without code changes |
| Refactor (Re-architect) | Redesign applications using cloud-native features. | Microservices / cloud-native redesign |
| Repurchase | Replace with a SaaS solution. | Replace with SaaS |
| Retire | Decommission applications no longer needed. | Decommission / shut down |
| Retain | Keep applications on-premises for now. | Keep on-premises / not ready to migrate |
| Relocate | Move infrastructure without modification, often using VMware. | Move as-is / VMware migration |
- Economies of scale lowers variable costs; trading fixed for variable eliminates CapEx. These are distinct benefits.
- Elasticity is automatic and bidirectional. Scalability is growth without automatic release.
- "Test recovery" maps to Reliability. "Improve processes" maps to Operational Excellence.
- Multi-AZ provides high availability within a Region. Multi-Region provides geographic disaster tolerance.
- Rehost = as-is. Replatform = optimize without code changes. Refactor = redesign.
You have the vocabulary. Can you apply it under exam pressure? AWS phrases questions in ways that turn familiar concepts into distractors. Reading is only half the preparation.
- Domain-specific questions targeting Cloud Concepts distinctions
- Instant score breakdown — see exactly where you lose points
- Explanations written in the same instructor voice as this guide
- Built for CLF-C02's question style — no generic filler
Security and Compliance represents the second-largest domain on the exam. The Shared Responsibility Model appears in multiple questions, sometimes directly and sometimes as context for a scenario. Understanding the boundary between AWS responsibilities and customer responsibilities is essential before studying individual security services.
2.1 The Shared Responsibility Model
The Shared Responsibility Model defines what AWS manages and what the customer manages. This concept appears directly in exam questions and also provides context for questions about specific services.
Security OF the cloud = AWS. Security IN the cloud = Customer.
A useful heuristic: anything you configure in the AWS Console is your responsibility. Anything that lives in the data center is AWS's responsibility.
| Responsibility | Typically Managed By | Examples |
|---|---|---|
| Physical security | AWS | Data center access, hardware disposal, facility security |
| Hypervisor and virtualization layer | AWS | The software layer beneath EC2 instances |
| Managed service operating systems | AWS | RDS database OS, Lambda runtime environment |
| Automated RDS backup mechanism | AWS | AWS provides the backup mechanism. Customer configures retention period. |
| IAM configuration | Customer | Users, roles, groups, policies, MFA settings |
| Guest operating system patching | Customer | EC2 instance OS updates |
| Data encryption choices | Customer | Whether to enable encryption, which keys to use |
| Security group and NACL rules | Customer | Firewall configuration for EC2 and subnets |
| Application code | Customer | Lambda function code, application logic |
How the Boundary Shifts Based on Service Type
The division of responsibility changes depending on whether a service is managed by AWS or self-managed. This distinction is frequently tested.
| Scenario | Responsibility | Reasoning |
|---|---|---|
| Patching the RDS database OS | AWS | RDS is a managed service. AWS owns and patches the OS. |
| Configuring RDS backup retention period | Customer | Configuration choices remain with the customer. |
| Creating IAM users and assigning roles | Customer | Identity configuration is always the customer's responsibility. |
| Securing the physical S3 hardware | AWS | Physical infrastructure is always AWS's responsibility. |
| Configuring security groups for EC2 | Customer | Firewall rules are customer-configured. |
| Patching the EC2 guest operating system | Customer | EC2 is self-managed at the OS level. |
For managed services like RDS, AWS manages the backup infrastructure — the automated mechanism that creates backups. However, the customer configures the backup retention period and whether automated backups are enabled.
If a question asks who is responsible for configuring backups, the answer is the customer. If it asks who provides the backup mechanism, the answer is AWS.
2.2 AWS Identity and Access Management (IAM)
IAM controls authentication (who can sign in) and authorization (what they can do). The exam tests whether you know when to use each IAM entity type.
| Entity | Use Case | Credentials |
|---|---|---|
| IAM User | A specific person or application that needs long-term AWS access. | Username/password, access keys |
| IAM Role | An entity that assumes temporary permissions. Used by EC2, Lambda, and federated users. | Temporary credentials via STS |
| IAM Group | A collection of users who share the same permissions. | No credentials; policies only |
| IAM Policy | A JSON document defining permissions. | Attached to users, groups, or roles |
Applications running on EC2 should use IAM Roles, not IAM Users.
Roles provide temporary credentials that rotate automatically through the AWS Security Token Service (STS). Creating an IAM user with long-term access keys for an application is a security anti-pattern and is typically an incorrect answer on the exam.
2.3 Security Services — What Each Service Does
The exam tests whether you can select the correct security service for a described scenario. Each service has a distinct primary function.
| Service | Primary Function | Does It Block Traffic? |
|---|---|---|
| AWS Shield Standard | Automatic protection against common DDoS attacks at Layers 3 and 4. | Yes (automatic) |
| AWS Shield Advanced | Enhanced DDoS protection with access to the Shield Response Team (SRT). | Yes, plus SRT |
| AWS WAF | Filter HTTP/HTTPS traffic to block SQL injection, XSS, and bot traffic (when configured). | Yes (when configured) |
| Amazon GuardDuty | Continuous threat detection using machine learning. Identifies malicious activity. | No — detects only |
| Amazon Inspector | Automated vulnerability scanning for EC2 instances and container images. | No — assesses only |
| Amazon Macie | Discovers and classifies sensitive data (PII, PHI) stored in Amazon S3. | No — discovers only |
| AWS KMS | Create and manage encryption keys used to encrypt data at rest. | N/A |
| AWS Secrets Manager | Store and automatically rotate database credentials and API keys. | N/A |
| AWS CloudTrail | Record API calls for audit — who did what and when. | No — logs only |
| AWS Artifact | Self-service access to AWS compliance reports (SOC, PCI, ISO). | N/A |
How to Select the Right Security Service
| Scenario Language | Correct Service | Reasoning |
|---|---|---|
| Who deleted or modified a resource | AWS CloudTrail | API audit log records identity and action |
| Compliance report (SOC, PCI, ISO) | AWS Artifact | Self-service compliance documentation |
| Threat detection / malicious activity | Amazon GuardDuty | Continuous threat identification |
| Vulnerability scan / CVE assessment | Amazon Inspector | Automated vulnerability scanning |
| Sensitive data in S3 / PII / PHI | Amazon Macie | Data discovery and classification in S3 |
| SQL injection / XSS / bot traffic | AWS WAF | Application-layer HTTP filtering (when configured) |
| DDoS flood / network attack | AWS Shield | Network-layer DDoS protection |
| Access to Shield Response Team (SRT) | AWS Shield Advanced + Business Support+ | SRT requires both Shield Advanced and Business Support or higher |
2.4 Network Security: Security Groups vs Network ACLs
Both control network traffic, but they operate at different levels and have different behaviors. The exam tests whether you know which one applies to a given requirement.
| Property | Security Group | Network ACL |
|---|---|---|
| Applies to | Instance level (e.g., EC2, RDS) | Subnet level |
| State | Stateful — return traffic is automatically allowed | Stateless — return traffic must be explicitly allowed |
| Rule types | Allow rules only | Allow and deny rules |
| Evaluation | All rules evaluated before decision | Rules evaluated in numerical order |
Security Group = Stateful + Instance-level
Network ACL = Stateless + Subnet-level
These four attributes are the most commonly tested distinctions between the two.
2.5 Identity Federation and Single Sign-On
Two services handle different identity scenarios. Understanding their intended users prevents confusion.
| Service | Use Case | User Type |
|---|---|---|
| Amazon Cognito | Sign-up and sign-in for your application's end users (customers). | External users |
| AWS IAM Identity Center | Single sign-on for workforce users across multiple AWS accounts and business applications. | Employees / workforce |
Cognito = your customers. IAM Identity Center = your employees.
Scenario Practice
| Scenario | Correct Answer | Reasoning |
|---|---|---|
| Security team needs to identify who deleted a production database. | AWS CloudTrail | CloudTrail records API activity and identity. |
| Compliance team needs to download a PCI DSS attestation. | AWS Artifact | Artifact provides self-service compliance reports. |
| An EC2 instance is communicating with a known malicious IP. | Amazon GuardDuty | GuardDuty detects threats and alerts. |
- RDS OS patching = AWS responsibility. RDS backup retention configuration = customer responsibility.
- EC2 applications should use IAM Roles, not IAM Users.
- GuardDuty detects. Inspector scans. WAF blocks HTTP (when configured). Shield blocks DDoS.
- CloudTrail records WHO did WHAT. CloudWatch monitors performance metrics. AWS Config tracks configuration compliance.
- Security Group = stateful + instance-level. Network ACL = stateless + subnet-level.
- SRT access requires Shield Advanced + Business Support or higher.
- Cognito = external customer identity. IAM Identity Center = workforce SSO.
Domain 2 is 30% of your exam — roughly 20 questions you cannot afford to misread. You've learned the Shared Responsibility splits, security service verbs, and stateful vs stateless. Now the real question: are those patterns automatic yet?
- Shared Responsibility scenarios phrased exactly like the real exam
- GuardDuty vs Inspector vs WAF discrimination drills
- IAM Role vs User trap questions — the way AWS actually writes them
- CloudTrail vs CloudWatch vs Config separation under timed pressure
This is the largest domain on the exam, and it rewards a specific skill: recognizing which service or feature fits a described requirement. You do not need deep architectural knowledge. You need to distinguish services that sound similar but solve different problems.
3.1 EC2 Purchasing Options
Amazon EC2 offers several purchasing models, each designed for a different workload pattern. The exam tests whether you can match a described workload to the most cost-effective option.
| Option | Commitment | Typical Discount | Best For |
|---|---|---|---|
| On-Demand | None | Baseline rate | Unpredictable or short-term workloads, development and testing |
| Reserved Instances (Standard) | 1 or 3 years | Up to 72% | Steady-state workloads with predictable instance families |
| Reserved Instances (Convertible) | 1 or 3 years | Lower than Standard | Steady-state workloads where you may need to change instance family |
| Spot Instances | None | Up to 90% | Fault-tolerant, stateless, or batch workloads |
| Savings Plans | 1 or 3 years (hourly commitment) | Up to 72% | Flexible commitment across EC2, Lambda, and Fargate |
| Dedicated Hosts | Varies | BYOL | Physical server isolation for licensing or compliance requirements |
How to Select the Right Purchasing Option
| Scenario Language | Correct Option | Reasoning |
|---|---|---|
| Cannot tolerate interruption / steady-state 24/7 | Reserved Instances | Spot's interruption risk eliminates it |
| Cheapest option / workload can be interrupted | Spot Instances | Up to 90% discount in exchange for interruption risk |
| No commitment / short-term / unpredictable | On-Demand | No upfront commitment required |
| Maximum savings / 3-year / fixed instance family | Standard Reserved Instance (All Upfront) | Deepest discount with commitment |
| Physical server / license compliance / BYOL | Dedicated Host | Physical isolation for licensing requirements |
Standard Lambda synchronous invocations are limited to 15 minutes. This is the limit tested on CLF-C02.
However, Lambda Managed Instances support up to 90 minutes for asynchronous invocations. Event Source Mapping invocations (except Amazon MQ and DocumentDB) also support 90 minutes on Managed Instances.
Exam guidance: For standard Lambda functions, 15 minutes is the limit. If a scenario describes a job exceeding 15 minutes and does not mention Managed Instances, the correct alternative is Fargate or AWS Batch.
3.2 Amazon S3 Storage Classes
S3 offers multiple storage classes, each optimized for different access patterns and cost requirements. The exam tests whether you can select the appropriate class for a described scenario.
| Storage Class | Designed For | Retrieval Options |
|---|---|---|
| S3 Standard | Frequently accessed data | Millisecond access, no restore needed |
| S3 Standard-IA | Infrequently accessed data requiring immediate access | Millisecond access, no restore needed |
| S3 Intelligent-Tiering | Unknown or changing access patterns | Automatic tiering; no retrieval fees |
| S3 Glacier Instant Retrieval | Long-term archive accessed quarterly, requiring immediate access | Millisecond access; no restore request required |
| S3 Glacier Flexible Retrieval | Archive data accessed 1–2 times per year, hours acceptable | Expedited: 1–5 min (objects <250MB) Standard: 3–5 hours Bulk: 5–12 hours |
| S3 Glacier Deep Archive | Compliance archives, long-term retention (7–10+ years) | Standard: Within 12 hours Bulk: Within 48 hours Expedited not available |
Do not assume all S3 Glacier storage classes share the same retrieval characteristics.
- S3 Glacier Instant Retrieval provides real-time access with no restore request. It is designed for data accessed once per quarter.
- S3 Glacier Flexible Retrieval and S3 Glacier Deep Archive require a restore operation before data can be accessed.
- Expedited retrieval is only available for S3 Glacier Flexible Retrieval, not for Deep Archive.
If a scenario requires immediate access without a restore step, Glacier Instant Retrieval is the correct choice. If hours are acceptable and cost matters more, Glacier Flexible (Bulk) or Deep Archive (Bulk) applies.
3.3 Database Services
AWS offers purpose-built database services. The exam tests whether you can identify the right service for a described data model or workload.
| Service | Database Type | Typical Use Case |
|---|---|---|
| Amazon RDS | Managed relational (SQL) | Traditional applications, ERP, CRM, e-commerce |
| Amazon Aurora | Cloud-native relational | MySQL/PostgreSQL-compatible with higher performance |
| Amazon DynamoDB | NoSQL key-value and document | Serverless, single-digit millisecond performance at scale |
| Amazon Redshift | Data warehouse | Petabyte-scale analytics and business intelligence |
| Amazon ElastiCache | In-memory cache | Microsecond latency caching with Redis or Memcached |
| Amazon Neptune | Graph database | Highly connected datasets, fraud detection, social networks |
| Amazon Timestream | Time-series database | IoT sensor data, telemetry, time-based metrics |
How to Select the Right Database
| Scenario Language | Correct Service | Reasoning |
|---|---|---|
| Graph queries / fraud detection / relationships | Amazon Neptune | Purpose-built for graph data |
| Data warehouse / petabyte analytics | Amazon Redshift | Optimized for analytical workloads |
| NoSQL / single-digit ms / millions of requests | Amazon DynamoDB | Serverless NoSQL with consistent low latency |
| In-memory / microsecond / caching | Amazon ElastiCache | In-memory caching for performance |
| High availability for RDS | Multi-AZ deployment | Synchronous standby with automatic failover |
| Read scaling for RDS | Read Replicas | Asynchronous replication for read performance |
Multi-AZ provides high availability through a synchronous standby database with automatic failover. Read Replicas provide read scaling through asynchronous replication. These serve different purposes and are not interchangeable.
"High availability" or "automatic failover" points to Multi-AZ. "Read performance" or "read scaling" points to Read Replicas.
3.4 Networking Services
The exam tests whether you can select the appropriate networking service for a described connectivity or performance requirement.
| Requirement | Service | Key Characteristic |
|---|---|---|
| Dedicated private connection, no public internet | AWS Direct Connect | Private physical network connection |
| Encrypted tunnel over public internet | AWS Site-to-Site VPN | Quick to set up, uses internet |
| Connect many VPCs in a hub-and-spoke topology | AWS Transit Gateway | Central hub for VPC connectivity |
| Cache content globally for lower latency | Amazon CloudFront | CDN with edge caching |
| Route live traffic over the AWS global network | AWS Global Accelerator | Improves performance for live traffic |
| HTTP/HTTPS load balancing | Application Load Balancer | Layer 7, path-based routing |
| TCP/UDP extreme performance | Network Load Balancer | Layer 4, high throughput |
CloudFront caches content at edge locations to reduce latency for static and dynamic content. Global Accelerator routes live traffic over the AWS backbone to improve performance without caching. "Cache" points to CloudFront. "Route live" points to Global Accelerator.
3.5 Management and Monitoring Tools
Three AWS services are commonly confused. Each answers a different question.
| Service | Primary Question | Data Type |
|---|---|---|
| AWS CloudTrail | Who did what and when? | API activity logs |
| Amazon CloudWatch | How is performance trending? | Metrics, logs, alarms |
| AWS Config | What is the configuration state? | Resource configuration history |
CloudTrail records API calls — the audit trail of actions. CloudWatch monitors performance metrics and logs. Config tracks resource configuration changes and evaluates compliance against desired settings.
3.6 AI, Machine Learning, and Analytics Services
The exam tests whether you can identify the correct AI/ML or analytics service for a described use case.
| Service | Function | Use Case |
|---|---|---|
| Amazon SageMaker | Full ML lifecycle | Build, train, and deploy machine learning models |
| Amazon Bedrock | Foundation models as API | Generative AI without managing infrastructure |
| Amazon Rekognition | Image and video analysis | Object detection, facial analysis |
| Amazon Transcribe | Speech to text | Convert audio to text transcripts |
| Amazon Polly | Text to speech | Convert text to natural-sounding speech |
| Amazon Textract | Document text extraction | Extract text and data from scanned documents |
| Amazon Athena | Serverless SQL on S3 | Query data in S3 without ETL |
| AWS Glue | Serverless ETL | Prepare and transform data for analytics |
| Amazon QuickSight | Business intelligence | Create dashboards and visualizations |
| Amazon Kinesis | Real-time streaming | Ingest and process streaming data |
- Transcribe = speech to text. Polly = text to speech.
- Rekognition = images and video. Textract = documents and forms.
- Athena = SQL on S3. Glue = ETL. QuickSight = visualization.
- Reserved Instances are for steady-state workloads. Spot is for interruptible workloads. On-Demand is for unpredictable workloads.
- S3 Glacier Instant Retrieval provides real-time access without a restore request. Flexible and Deep Archive require restore operations.
- Multi-AZ provides high availability for RDS. Read Replicas provide read scaling.
- Direct Connect is a private connection. VPN is encrypted over the internet.
- CloudTrail records WHO did WHAT. CloudWatch monitors performance. Config tracks configuration state.
- Neptune = graph. Redshift = warehouse. DynamoDB = NoSQL. ElastiCache = in-memory cache.
Technology & Services is the biggest domain at 34% of your score — about 22 questions. You've internalized the Decision Matrices and trigger words. But this is where AWS hides its craftiest distractors: Lambda vs Fargate, CloudFront vs Global Accelerator, Multi-AZ vs Read Replicas.
- EC2 purchasing scenarios with realistic multi-option distractors
- S3 storage class selection — including the retrieval options distinction
- Database selection: Neptune, Redshift, DynamoDB, ElastiCache discrimination
- Networking and AI/ML service identification under real exam conditions
This domain has the smallest exam weight but is highly predictable. The cost management tools and support plan tiers follow consistent patterns. Master these, and you can secure these points efficiently.
4.1 Cost Management Tools
Four AWS tools handle different aspects of cost management. Each operates in a different time frame or serves a different purpose.
| Tool | Purpose | When to Use |
|---|---|---|
| AWS Pricing Calculator | Estimate costs before deployment | Planning phase — "What will this cost?" |
| AWS Cost Explorer | Analyze historical costs and usage | Review phase — "What did we spend and why?" |
| AWS Budgets | Set spending limits and receive alerts | Ongoing — "Alert me when spending exceeds a threshold" |
| AWS Cost and Usage Report | Most granular line-item billing data | Detailed analysis — "I need raw data for chargeback" |
| Scenario Language | Correct Tool | Reasoning |
|---|---|---|
| Estimate before deployment | Pricing Calculator | Future costs = Pricing Calculator |
| Visualize past spending trends | Cost Explorer | Past analysis = Cost Explorer |
| Alert when spending exceeds threshold | AWS Budgets | Limits and alerts = Budgets |
| Granular line-item data for chargeback | Cost and Usage Report | Raw detail = CUR |
4.2 AWS Support Plans
AWS offers multiple support plans. The exam tests whether you can identify which plan provides a specific feature.
AWS has announced significant changes to its support plans:
- Developer Support will be discontinued on January 1, 2027. Customers can continue using their existing plan or upgrade to Business Support+ before that date.
- Enterprise On-Ramp will be discontinued on January 1, 2027. Throughout 2026, Enterprise On-Ramp customers will be automatically upgraded to Enterprise Support during contract renewal. The upgraded Enterprise Support includes a designated TAM, 15-minute response times, and a lower $5,000 minimum (reduced from $15,000).
- Business Support+ is the current name for the Business tier, offering AI-powered support and 24/7 access to AWS engineers.
- These changes apply to commercial AWS Regions only. Developer Support, Business Support, and Enterprise On-Ramp remain available in AWS GovCloud (US).
Exam guidance: For current CLF-C02 exam versions, Enterprise On-Ramp remains a valid answer for TAM-related questions. Be aware that future exam versions may reflect the discontinuation.
| Plan | Minimum Monthly Cost | Key Features |
|---|---|---|
| Basic | Free | Account and billing support, service quota increases, documentation |
| Developer | $29 or 3% of monthly usage (whichever is greater) | Email support during business hours. End of support: January 1, 2027 |
| Business Support+ | $100 or tiered percentage (10%/7%/5%/3%) (whichever is greater) | 24/7 phone, chat, and web. Full Trusted Advisor access. |
| Enterprise On-Ramp | $5,500 minimum | Pool of TAMs, Concierge support. End of support: January 1, 2027 |
| Enterprise | $15,000 minimum (may be reduced to $5,000 for upgraded On-Ramp customers) | Designated TAM, 15-minute response for business-critical, Security Incident Response |
| Unified Operations | $50,000+ | Domain Specialist Engineers, AWS Countdown Premium, proactive incident management. New highest tier. |
How to Select the Right Support Plan
| Scenario Language | Correct Plan | Reasoning |
|---|---|---|
| Full Trusted Advisor at lowest cost | Business Support+ | Full TA access requires Business tier or higher |
| Designated Technical Account Manager (TAM) | Enterprise | Designated TAM is Enterprise-only |
| 24/7 phone support at lowest cost | Business Support+ | 24/7 phone access begins at Business tier |
| Access to Shield Response Team (SRT) | AWS Shield Advanced + Business Support+ | SRT is NOT a support plan feature; it requires Shield Advanced and Business Support or higher |
Access to the Shield Response Team (SRT) is not included in any AWS Support plan alone. SRT access requires AWS Shield Advanced combined with Business Support or higher. This distinction appears in exam questions that describe DDoS response requirements.
4.3 AWS Organizations and Control Tower
These services help manage multiple AWS accounts, but they serve different purposes.
| Service | Primary Purpose | Key Capability |
|---|---|---|
| AWS Organizations | Centralized management of multiple accounts | Consolidated billing, Service Control Policies (SCPs) |
| AWS Control Tower | Set up and govern a multi-account environment | Automated account provisioning with guardrails |
AWS Organizations provides consolidated billing and policy-based controls (SCPs). Control Tower sets up a governed multi-account environment with best-practice configurations.
4.4 Reserved Instance Rules
Reserved Instances offer significant discounts in exchange for commitment. The exam may test whether you understand the difference between Standard and Convertible RIs.
| RI Type | Discount Level | Flexibility | Sellable on Marketplace? |
|---|---|---|---|
| Standard RI | Higher discount (up to 72%) | Fixed instance family | Yes — RI Marketplace |
| Convertible RI | Lower discount | Can change instance family | No |
| Savings Plans | Up to 72% | Applies across EC2, Lambda, Fargate | N/A |
Scenario Practice
| Scenario | Correct Answer | Reasoning |
|---|---|---|
| Finance wants automatic alerts when monthly spend exceeds $10,000. | AWS Budgets | Threshold-based alerts = Budgets |
| Architect needs to estimate costs before deploying 100 EC2 instances. | AWS Pricing Calculator | Pre-deployment estimation = Pricing Calculator |
| Company needs one invoice for eight AWS accounts with shared discounts. | AWS Organizations | Consolidated billing = Organizations |
- Pricing Calculator = future estimates. Cost Explorer = past analysis. Budgets = limits and alerts. CUR = raw detailed data.
- Business Support+ is the lowest tier with full Trusted Advisor access.
- Designated TAM requires Enterprise Support. SRT requires Shield Advanced + Business Support or higher.
- Organizations provides consolidated billing and SCPs. Control Tower sets up governed multi-account environments.
- Standard RIs are sellable on the RI Marketplace. Convertible RIs are not.
- Developer Support and Enterprise On-Ramp have announced end-of-support dates in 2027.
Eight questions. Four cost tools. Six support tiers. If the patterns clicked as you read, Domain 4 should feel like free points. But "felt clear while reading" and "fires correctly in 83 seconds under exam pressure" are two different things.
- Pricing Calculator vs Cost Explorer vs Budgets — same-question distractor drills
- Support plan tier questions with SRT / TAM / Full TA precision
- Organizations vs Control Tower scenario discrimination
- Reserved Instance rules: Standard vs Convertible vs Savings Plans
You don't need to know the right answer to eliminate three wrong ones. AWS builds its wrong answers with tells — phrases that reveal they're incorrect before you've even finished reading them. This chapter trains you to see those tells automatically.
5.1 High-Confidence Eliminators
Every phrase below is almost always wrong. The moment you see one, you can eliminate the answer without reading further.
5.2 Managed Service Elimination Rules
For any managed service (RDS, Lambda, DynamoDB, Fargate) — if the answer says the customer must do any of the following, eliminate it immediately:
| If the Answer Says Customer Must... | Reality Check |
|---|---|
| Patch the operating system | RDS, Lambda — AWS owns and patches the OS. You never touch it. |
| Manage automated backups | Amazon RDS — AWS automates the backup mechanism. Customer configures retention period. |
| Configure server capacity | Lambda, Fargate — Serverless = AWS manages this. |
| Replace failed hardware | All managed services — AWS handles all hardware. |
| Monitor the hypervisor | EC2, RDS — Virtualization layer = AWS. Always. |
5.3 Most Confused Service Pairs
| Pair | How to Separate Them |
|---|---|
| CloudTrail vs CloudWatch | Trail = WHO did WHAT (audit). Watch = WHAT metrics (performance). Completely different questions. |
| Shield vs WAF | 'DDoS/flood' = Shield. 'SQL injection/XSS/bots' = WAF. Different threat layers. |
| Inspector vs GuardDuty | Inspector = proactive SCAN. GuardDuty = continuous DETECT. |
| Multi-AZ vs Read Replicas | 'High availability/failover' = Multi-AZ. 'Read scaling' = Read Replicas. NEVER swap. |
| Secrets Manager vs Parameter Store | Auto-rotation for RDS = Secrets Manager. Basic storage = Parameter Store. |
| CloudFront vs Global Accelerator | CloudFront = CDN CACHE. Global Accelerator = live ROUTE. |
| Cognito vs IAM Identity Center | Cognito = app CUSTOMERS. Identity Center = EMPLOYEES. |
Stop all new material 12 hours before the exam. No new services. No new concepts. What you don't know tonight, you won't know in the exam room. Read every anchor below OUT LOUD. The rhythm is engineered for spoken recall.
The Rhythmic Anchors — Speak Them, Don't Just Read Them
Exam-Day Protocol
| Time | Action |
|---|---|
| T-12 hrs | Stop all new material. Read anchors aloud once. Sleep early. |
| T-2 hrs | Read the Morning-Of Checklist (Bonus 3). Anchors once more. |
| T-0 | Read every question stem fully. Classify type before reading choices. |
| Stuck | Apply High-Confidence Eliminators. Flag and move. Never stall on one question. |
| Review | Never change answers without a specific, concrete reason. |
Format: Trap → Why It's Tempting → How to Distinguish. For each trap, ask yourself: "Would I have fallen for that?" If the answer is yes — that's your personal study target. Candidates who fall into these traps lose an average of 8–12 points.
These 100 trigger phrases appear in CLF-C02 question stems. Cover the Answer column. Read a trigger phrase. Say the answer out loud before your eyes reach it. That's the level of automaticity you need.
| # | Trigger Phrase | Answer | Why |
|---|---|---|---|
| 1 | who deleted / modified / created resource | AWS CloudTrail | WHO = CloudTrail always |
| 2 | API call audit / history | AWS CloudTrail | Audit = CloudTrail |
| 3 | CPU metrics / performance alarms | Amazon CloudWatch | Metrics = CloudWatch |
| 4 | configuration compliance / drift detection | AWS Config | Config state = AWS Config |
| 5 | compliance report / SOC / PCI / ISO | AWS Artifact | Reports = Artifact |
| 6 | best-practice recommendations | AWS Trusted Advisor | Recs = Trusted Advisor |
| 7 | threat detection / malicious activity | Amazon GuardDuty | Active threat = GuardDuty |
| 8 | vulnerability scan / CVE assessment | Amazon Inspector | CVE = Inspector |
| 9 | sensitive data in S3 / PII / PHI | Amazon Macie | S3 data = Macie |
| 10 | DDoS protection / flood attack | AWS Shield | DDoS = Shield |
| 11 | SRT / Shield Response Team | AWS Shield Advanced + Business Support+ | SRT requires both Shield Advanced and Business Support or higher |
| 12 | SQL injection / XSS / bots / geo-block | AWS WAF | HTTP attacks = WAF (when configured with rules) |
| 13 | auto-rotate DB credentials / passwords | AWS Secrets Manager | Auto-rotation = Secrets Manager |
| 14 | workforce SSO / multiple AWS accounts | AWS IAM Identity Center | Employee SSO = Identity Center |
| 15 | app user sign-up / sign-in | Amazon Cognito | App customers = Cognito |
| 16 | serverless functions / event-driven | AWS Lambda | Serverless code = Lambda |
| 17 | serverless containers / no clusters | AWS Fargate | Serverless containers = Fargate |
| 18 | spot / cheapest / tolerates interruption | EC2 Spot Instances | Cheapest + interruptible = Spot |
| 19 | unknown access patterns / auto-tier | S3 Intelligent-Tiering | Auto-tiering: 30d→IA, 90d→Archive Instant. Objects <128KB remain Frequent. |
| 20 | rare + immediate / millisecond archive | Glacier Instant Retrieval | No restore required. Millisecond access for quarterly data. |
| 21 | graph queries / fraud / relationships | Amazon Neptune | Graph = Neptune |
| 22 | data warehouse / petabyte analytics | Amazon Redshift | Warehouse = Redshift |
| 23 | NoSQL / single-digit ms / serverless DB | Amazon DynamoDB | Serverless NoSQL = DynamoDB |
| 24 | in-memory / microsecond / Redis cache | Amazon ElastiCache | Microsecond cache = ElastiCache |
| 25 | no public internet / dedicated link | AWS Direct Connect | 'No public internet' = Direct Connect |
| 26 | cache content globally / CDN | Amazon CloudFront | CDN cache = CloudFront |
| 27 | route live traffic / AWS backbone | AWS Global Accelerator | Live routing = Accelerator |
| 28 | infrastructure as code / IaC templates | AWS CloudFormation | IaC = CloudFormation |
| 29 | estimate before building / migration | AWS Pricing Calculator | BEFORE = Pricing Calculator |
| 30 | analyze past costs / visualize spend | AWS Cost Explorer | PAST = Cost Explorer |
| 31 | set budget limit / alert threshold | AWS Budgets | Limit + alert + budget actions = Budgets. |
| 32 | consolidated billing / single invoice | AWS Organizations | One invoice = Organizations |
| 33 | TAM / Technical Account Manager | Enterprise Support | TAM = Enterprise tier |
| 34 | full Trusted Advisor / all TA checks | Business Support+ (min) | Full TA = Business Support+ min. Basic/Developer = Service Limits + 6 selected checks. |
| 35 | speech to text / transcribe audio | Amazon Transcribe | Speech→text = Transcribe |
| 36 | text to speech / voice output | Amazon Polly | Text→speech = Polly |
| 37 | foundation models / GenAI / LLM API | Amazon Bedrock | GenAI API = Bedrock |
| 38 | on-premises + same AWS APIs | AWS Outposts | On-prem AWS = Outposts |
| 39 | recover automatically from failure | Reliability Pillar | Auto-recover = Reliability |
| 40 | carbon footprint / minimize waste | Sustainability Pillar | Environmental = Sustainability |
This is your emergency protocol. 24 hours left. Do not open any other section. Do not search YouTube. Do not start a new course. Read this page. Read it again. Read the anchors out loud. Sleep. Execute.
Domain 1 — Cloud Concepts (24%)
- 6 Benefits: Trade fixed→variable | Economies of scale | Stop guessing capacity | Speed+agility | Stop data center spending | Go global in minutes
- Elasticity=auto UP+DOWN | Scalability=growth only | Reliability=RECOVER | Durability=data persists
- 6 Pillars: OE=improve | Security=trace+protect | Reliability=recover | Performance=serverless | Cost=spend analysis | Sustainability=carbon
- Multi-AZ=HA within region | Multi-Region=geographic disaster resilience
- 7 Rs: Rehost=as-is | Replatform=managed+no code | Refactor=microservices | Repurchase=SaaS | Retire | Retain | Relocate=VMware
Domain 2 — Security & Compliance (30%)
- AWS owns: hardware, hypervisor, managed service OS, automated RDS backups, Lambda runtime
- Customer owns: IAM, EC2 guest OS, data, security groups, S3 policies, encryption config
- GuardDuty=DETECTS (no block) | Inspector=SCANS CVEs | Macie=PII in S3 | WAF=blocks HTTP | Shield=blocks DDoS
- CloudTrail=WHO did WHAT | CloudWatch=WHAT metrics | Config=WHAT config state
- Security Group=stateful+instance | Network ACL=stateless+subnet | SRT=Shield Advanced + Business Support+
Domain 3 — Technology & Services (34%)
- EC2: Spot=cheapest/interruptible | Reserved 3yr All Upfront=max savings | On-Demand=no commitment | Savings Plans=flexible
- Lambda=15min sync; 90min async on Managed Instances | Fargate=serverless containers | Beanstalk=PaaS web
- S3 Glacier retrieval: Instant=millisecond, no restore, quarterly access | Flexible=Expedited 1–5 min, Standard 3–5 hr, Bulk 5–12 hr | Deep Archive=Standard 12 hr, Bulk 48 hr, no expedited
- Neptune=graph | Redshift=warehouse | DynamoDB=NoSQL | ElastiCache=in-memory | Multi-AZ=HA | Read Replicas=performance
- Direct Connect=no internet+weeks | VPN=encrypted internet+hours | Transit Gateway=hub-and-spoke
- CloudFront=CDN | Global Accelerator=backbone | CloudFormation=IaC
- Transcribe=speech→text | Polly=text→speech | Athena=SQL on S3 | Glue=ETL | QuickSight=BI
Domain 4 — Billing & Pricing (12%)
- Pricing Calculator=FUTURE estimate | Cost Explorer=PAST analysis | Budgets=LIMITS+ALERTS | CUR=raw granular data
- Support (2026): Basic=free | Developer=$29 or 3% (EOS Jan 1, 2027) | Business Support+=$100 or tiered (full TA) | Enterprise On-Ramp=$5,500 (EOS Jan 1, 2027) | Enterprise=$15k min (reduced to $5k for upgraded On-Ramp customers) | Unified Operations=$50k+ (new top tier).
- Full TA=Business Support+ minimum | SRT=Shield Advanced + Business Support+ | TAM=Enterprise
- Organizations=consolidated billing+SCPs | Control Tower=multi-account governance setup
- ✕ 'GuardDuty automatically blocks' → GuardDuty never blocks
- ✕ 'Manually patch RDS OS' → AWS owns RDS OS
- ✕ 'Lambda for 4-hour job' → Lambda sync max = 15 min
- ✕ 'CloudWatch to find who deleted X' → WHO = CloudTrail
- ✕ 'SRT via Enterprise Support alone' → SRT requires Shield Advanced + Business Support+
- ✕ 'Reserved Instances for unpredictable workloads' → RIs need commitment
- ✕ 'S3 Glacier for real-time access' → Glacier = archive
Rhythmic Anchors — Say These Out Loud
AWS is not just testing your knowledge of AWS. It is testing your ability to read precisely. Every technique below is a mechanism designed to make you pick the answer you recognize rather than the answer that's correct.
Technique 1 — The Distractor Answer
AWS places one answer that is technically correct in isolation — but wrong for the specific scenario.
"A company needs to recover its RDS database automatically during a failure. Which feature provides this?"
- A: Read Replicas ✗ — real RDS feature, but wrong purpose
- B: Multi-AZ deployment ✓ — automatic failover = Multi-AZ's entire purpose
Always read the scenario trigger word BEFORE scanning answers. 'Automatically recover' locks you to Multi-AZ before you've even seen the options.
Technique 2 — The Partial Correctness Trap
Two answer choices are partially correct. One addresses the scenario completely. One addresses only part of it.
Technique 3 — The Keyword Swap
AWS places a service that is 99% correct for a related scenario — but wrong for the exact scenario due to one swapped capability:
- GuardDuty vs Inspector (detect vs scan)
- CloudFront vs Global Accelerator (cache vs route)
- Multi-AZ vs Read Replicas (HA vs read performance)
Technique 4 — The Managed Service Responsibility Trap
- Customer owns: data, access control, configuration choices
- AWS owns: OS, patching, backup mechanism, hardware, hypervisor
The boundary shifts depending on whether the service is managed. RDS? AWS patches the OS. EC2? You patch the OS.
Technique 5 — The Scope Mismatch
- VPC Peering connects VPCs — but point-to-point. Many VPCs = Transit Gateway.
- EBS is block storage — single-instance only. Multi-instance = EFS.
- Security Groups work — at instance level only. Subnet = NACL.
Tier 1 concepts are heavily tested. Tier 2 appears occasionally. Tier 3 appears rarely.
Note: The specific claim that Tier 1 concepts appear in a set number of questions per exam is not published by AWS. This tier list reflects commonly tested concepts based on exam guide alignment, not official per-concept question counts.
Tier 1 — Must Master First (60% of study time)
| Concept / Service | Domain | Why It's Critical |
|---|---|---|
| Shared Responsibility Model | D2 | Direct questions + embedded in other questions as context |
| IAM — Users / Roles / Groups | D2 | Appears in compute, storage, security, and architecture questions |
| EC2 Purchasing Options | D3 | Reserved vs Spot vs On-Demand appears multiple times per exam |
| AWS CloudTrail | D2/D3 | 'WHO' questions — the most common single-service question type |
| Well-Architected 6 Pillars | D1 | Direct pillar questions every exam + architecture scenario context |
| S3 Storage Classes | D3 | Storage class selection — highly predictable |
| The 4 Cost Management Tools | D4 | Pricing Calculator / Explorer / Budgets / CUR |
| The Support Plan Tiers | D4 | Trusted Advisor + TAM + SRT questions |
| Security Service Map | D2 | GuardDuty/Inspector/WAF/Shield/Macie |
You have done the work. This checklist is not about cramming — it's about removing friction so your preparation can perform. Execute this like a pre-flight checklist. Nothing gets skipped.
| # | Item | What to Do |
|---|---|---|
| 1 | Verify Exam Slot & Time Zone | Log into Pearson VUE. Confirm exact start time in YOUR local time zone. |
| 2 | Prepare Government-Issued ID | Two forms of ID ready if testing online. |
| 3 | Test Webcam & Microphone | Run Pearson VUE's system test at least 30 minutes before your exam. |
| 4 | Close All Background Applications | Close everything: Slack, email, browser tabs. |
| 5 | Check Internet Connection | Use wired ethernet if possible. Run a speed test. |
| 6 | Clear Your Workspace | Desk clear: no papers, no notes, no second monitors, no books. |
| 7 | Hydrate & Eat a Real Meal | Eat a balanced meal 60–90 minutes before the exam. |
| 8 | Trust Your Sleep | Sleep consolidates memory. 7+ hours = better recall than last-minute cramming. |
| 9 | Read Rhythmic Anchors Once More | Open Chapter 6. Read the anchor pairs out loud once. Takes 4 minutes. |
| 10 | Set Pace & Breathe | 90 minutes / 65 questions = 83 seconds per question. Flag stuck questions and move forward. |
Now Simulate the Exam.
Every pattern in this guide has a corresponding question waiting to test it. Confirming you’re truly ready means facing CLF-C02-style pressure before the real thing — on your schedule, with instant feedback.
- 390+ realistic questions built to match CLF-C02’s question style and trap patterns
- 6 full 65-question exams — simulate complete exam sessions with real time pressure
- Domain-targeted filters — drill Cloud Concepts, Security, Technology, or Billing independently
- Explanations for every answer, written in the same instructor voice as this guide
- 6 months of unlimited access — one-time $29.99 per certification, no subscription
Designed exclusively for CLF-C02 · Pass on your first attempt.
Run through this once — you'll be surprised how many you already know, and how quickly the gaps fill in.
| Acronym | Full Name | One-Line Meaning |
|---|---|---|
| IAM | Identity and Access Management | Manage WHO can do WHAT on AWS resources |
| MFA | Multi-Factor Authentication | Second verification layer |
| STS | Security Token Service | Issues temporary credentials for roles and federation |
| SCP | Service Control Policy | Governance guardrail restricting what accounts can do in Organizations |
| VPC | Virtual Private Cloud | Your logically isolated network inside AWS |
| NACL | Network Access Control List | Stateless subnet-level firewall |
| SG | Security Group | Stateful instance-level firewall |
| IGW | Internet Gateway | Enables two-way internet access for public VPC subnets |
| NAT | Network Address Translation | Allows private subnets to reach internet outbound only |
| EC2 | Elastic Compute Cloud | Virtual server instances in the cloud |
| EBS | Elastic Block Store | Block storage attached to a single EC2 instance |
| EFS | Elastic File System | Managed NFS shared file system for multiple EC2 instances |
| S3 | Simple Storage Service | Scalable object storage |
| RDS | Relational Database Service | Managed SQL database |
| ALB | Application Load Balancer | Layer 7 HTTP/HTTPS load balancer with path-based routing |
| NLB | Network Load Balancer | Layer 4 TCP/UDP load balancer for extreme performance |
| KMS | Key Management Service | Create and manage encryption keys for AWS services |
| WAF | Web Application Firewall | Filter HTTP/HTTPS traffic — block SQL injection, XSS, bots (when configured) |
| IaC | Infrastructure as Code | Provision infrastructure via code/templates |
| CAF | Cloud Adoption Framework | AWS framework with 6 perspectives for planning cloud migration |
| RI | Reserved Instance | 1–3 year EC2 commitment for up to 72% discount |
| SRT | Shield Response Team | Available only via Shield Advanced + Business Support or higher |
| TAM | Technical Account Manager | Designated AWS advisor — Enterprise Support only |
| AZ | Availability Zone | Isolated data center within a Region |
| ETL | Extract, Transform, Load | Data pipeline process — AWS Glue is the managed ETL service |
| ML | Machine Learning | AI models that learn from data — SageMaker is AWS's full ML platform |
| LLM | Large Language Model | Foundation model for GenAI — Amazon Bedrock |