AWS Cloud Practitioner CLF C02
AWS Cloud Practitioner CLF C02
AWS Cloud Practitioner CLF C02
Introduction
● Introduction
o AWS Certified Cloud Practitioner is considered an entry-level certification, and
it's going to focus on your understanding of cloud computing concepts including
o This certification is designed for professionals who are new to cloud computing
and professionals seeking an understanding of cloud computing and all its
related concepts
o You will find that the first portion of this course is going to be focused on the big
picture theory and concepts related to cloud computing
▪ Cloud Migrations
1
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Global Infrastructure
▪ Connecting to AWS
o AWS Certified Cloud Practitioner has a maximum 65 questions over the course of
90 minutes
questions
▪ When you are taking the exam, you will not know which of the questions
2
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o To pass the AWS Certified Cloud Practitioner (CLF-C02) exam, you must score at
least 700 points out of 1,000 points that are available on the exam
o In order for you to take the exam, you will have to pay an exam fee by buying an
exam voucher
● Pearson VUE
● You can take it at any Pearson VUE testing center
worldwide, at either a local testing center or online
● You can buy that exam voucher by going to Pearson Vue
directly when you're scheduling your exam at
pearsonvue.com, or going to the voucher store at lpi.org
to buy it from their online store
● Pearson VUE and LPI have now created a capability for you
to take your certification exam online from the comfort of
your home or office, using the Pearson VUE OnVue testing
system
● AWS
● Go directly to the AWS certification page at
aws.training/certification
o 4 tips for success in this course
3
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● facebook.com/groups/diontraining
● Exam Tips
o There will be no trick questions
▪ At least one of the four listed possible answer choices that are written to
▪ When in doubt, choose the answer that is correct for the highest number
of situations
o Understand the key concepts of the test questions
o Do not memorize the terms word for word, try to understand them instead
o During the exam, the answers will be from multiple-choice style questions
4
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ You have nothing to lose here, but you do have to do your part and put in
some effort
o When you take those quizzes, you have to score at least an 80% for it to be
considered a pass in our system
o At the end of the course, you will find our practice exams
o Please don’t try to simply memorize the questions, but instead take the time to
understand the why behind them
o Make sure that you watched the videos, took the quizzes, did the labs, and
finished the practice exams
▪ If you’ve done all and don’t see the progress part at the top going from 0
▪ If you think you’ve done everything and it still doesn’t show 100%, please
email us at support@diontraining.com
o Once you have the course completion letter, you are eligible for our 60-Day 100%
Pass Guarantee
5
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Compute
▪ Storage
▪ Databases
▪ Machine Learning
▪ Artificial Intelligence
▪ Data Lakes
▪ Analytics
6
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o One of the strengths of AWS lies in the depth of functionality within its services
o AWS Partner Network (APN)
▪ Each region is designed to be isolated from the others, ensuring that they
▪ Distinct data centers equipped with their power, cooling, and networking
7
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o According to the National institute of Standards and Technology (or NIST) in their
Special Publication 800-145 entitled “The NIST Definition of Cloud Computing”,
there are five key benefits or features of cloud computing
▪ On-demand Self-service
● Key characteristic of cloud computing that enables users to quickly
and easily provision computing resources as needed, without the
need for human interaction
● On-demand self-service provides more agility and flexibility by
giving the ability to quickly scale up or down
● Also provides the ability to control the resources by allowing users
to easily provision additional resources
▪ Broad Network Access
● Allows users to access cloud computing resources from anywhere
with an Internet connection
● The increased mobility also allows organizations to change their
business models from a purely in-person model to a hybrid or
remote work capable organization
● Data can be accessed from anywhere which means the businesses
can maintain operations at all times
▪ Resource Pooling
● Enables cloud providers to dynamically allocate and reallocate
resources, such as servers and storage, as needed
● This leads to increased cost savings, more efficiency, improved
scalability, better disaster recovery, and additional flexibility for
the operations
8
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
9
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
10
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● Deployment Models
11
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o Each model has its own set of advantages and disadvantages, and the right
model for an organization will depend on its specific needs and requirements
o 6 Types of Cloud Deployment Models
▪ Public
● A third-party service provider makes resources available to the
end users over the Internet
● There are numerous public cloud solutions available today
including those from Amazon Web Services, Microsoft Azure, and
the Google Cloud Platform
● Public clouds can often be an inexpensive way for an organization
to gain a required service quickly and efficiently
● Advantages of public clouds include
● Lower costs
● Ability to scale resources quickly and easily
● Public clouds can be less secure than private clouds
▪ Private
● Cloud computing environment that is dedicated to a single
organization that the infrastructure, resources, and data are all
exclusively used by that organization
● The organization is responsible for the design, implementation,
and operation of the cloud resources and the servers that host
them
● AWS also offers Virtual Private Cloud (VPC) for users who want the
scalability of the cloud while maintaining a private, isolated
environment
● The advantages of private clouds include
12
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
13
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
maintenance costs
deployment solution
14
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o Cloud Deployment
o Hybrid Deployment
deployment model
leverage the benefits of the cloud, a hybrid model could be a good fit
o Multi-cloud Deployment
▪ Involves using more than one cloud service from different providers
▪ Business needs
▪ Budget
▪ Compliance requirements
▪ Technical capabilities
o The key to successful deployment model selection is aligning the model with
your organization's strategic objectives and operational needs
15
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Customer
including:
● Network security
● Physical security of the data centers
● Security of the virtualization layer
16
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ As Amazon Web Services puts it, the customer is responsible for security
“in” the cloud, while AWS is responsible for the security “of” the cloud
▪ AWS must manage the security of the cloud, ensuring the robustness and
data
o One advantage
▪ The shared responsibility model can also help to reduce the overall cost
of security
o Some disadvantages of the shared responsibility model
17
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
security tasks
o The shared responsibility model can be an effective way of ensuring that both
the cloud service provider and the customer are taking the necessary steps to
secure their respective parts of the cloud environment
18
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● Scaling
o Scaling
▪ Scalability
▪ Cost
▪ Ease of Management
19
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
to the system
o When choosing between horizontal and vertical scaling, there are several factors
to consider
▪ Type of workload
▪ Cost
● Redundancy
20
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o Redundancy
▪ High Availability
▪ Fault Tolerance
21
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Improved Performance
▪ Increased Resiliency
▪ Improved Security
● High Availability
o High Availability
22
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Minimized downtime
▪ Improved performance
▪ Increased resilience
▪ Improved security
o 4 key factors or events that can affect the levels of high availability we can
achieve in our cloud designs
▪ Network Connections
▪ Power Outages
▪ Natural Disasters
23
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● Disaster Recovery
o Disaster Recovery (DR)
disruption
o There are several strategies that organizations can implement to achieve disaster
recovery in cloud computing
▪ Replication
● Creates a second copy of the system and takes over in the event of
a disaster
▪ Failover
24
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Scalability
▪ Flexibility
▪ Cost Savings
25
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Availability
o Review and evaluate the disaster recovery plan to ensure it continues to meet
the organization's needs
● Recovery Objectives
o Recovery Objectives
26
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
27
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o 6 basic principles (Key Pillars) that lead to building successful cloud infrastructure
and applications
▪ Operational Excellence
● Focuses on managing and automating changes, monitoring
systems, and continuously improving procedures
● Application designs should also include infrastructure as code,
performance monitoring, and incident response planning
considerations
● Using something like CloudWatch, we can set up custom metrics
and alarms to proactively identify performance bottlenecks,
resource constraints, and anomalies
▪ Security
● Focuses on the protection of data, infrastructure, and assets
▪ Reliability
● Systems will maintain stability, recover from failures, and
consistently meet customers' needs
● AWS CloudWatch enables monitoring of AWS resources,
applications, and custom metrics
▪ Performance Efficiency
● Involves allocating the right resources to meet application
requirements, maintaining responsiveness, and optimizing costs
● AWS offers services like Amazon CloudFront, Amazon ElastiCache,
and Amazon S3 to cache and deliver content efficiently
▪ Cost Optimization
● Ensures that organizations obtain maximum value from their
resources while minimizing costs
28
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● AWS provides tools like AWS Cost Explorer and AWS Budgets to
monitor and analyze spending patterns
▪ Sustainability
● Addresses the increasing importance of making business better
for the environment
● AWS Lambda and other serverless services eliminate the need for
provisioning and managing servers
o To help companies address the six pillars, AWS offers the Well-Architected Tool
▪ Well-Architected Tool
● Comprehensive and invaluable resource for assessing and
optimizing cloud architectures to align with AWS best practices
and against the six pillars to identify ways to improve the
architecture
● This tool offers a series of questions and guidelines that help users
review their cloud infrastructure and identify potential areas for
improvement
▪ Service in the AWS Management Console that helps review the workload
▪ Operational Excellence
▪ Security
29
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Reliability
▪ Performance Efficiency
▪ Cost Optimization
▪ Sustainability
30
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
Cloud Migrations
Objective 1.3 - Understand the benefits of and strategies for migration to the AWS Cloud.
▪ On-premise environments are data centers and servers that are physically
▪ Advantages
● Improved scalability
● Increased accessibility
● Reduced costs
▪ Disadvantages
31
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Data and applications are transferred from one cloud service provider to
another
▪ Advantages
● Cost savings
● Migration can lead to improved performance and reliability
● Ability to take advantage of new features and services offered by
the new provider
▪ Disadvantages
● Time and effort required to move all the data and applications to
the new cloud environment
● There may be compatibility issues between the old and new cloud
environments
● Many cloud providers have large data transfer fees when moving
from one cloud provider to another
o Cloud environment to on-premise environment
▪ Advantages
32
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Disadvantages
33
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Data Migration
▪ Application Migration
▪ Infrastructure Migration
▪ Testing
34
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Performance Optimization
▪ Cost Optimization
35
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● Minimal downtime
● Cost-effective
● Improved performance
● Cost savings
● Improved flexibility
● Improved performance
● Scalability
● Cost savings
36
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
discontinuing the use of the old product without replacing it with a new
one
▪ Advantages
● Improved security
● Cost savings
37
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Disadvantages
● No modifications
● No disruption
● Customized solution
● Cost savings
38
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● Minimized risks
● Improved planning
▪ Used to build highly scalable, resilient, and flexible apps that can be
highly available
o Cloud native applications are usually built using containers and microservices
▪ Container
39
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● Scalability
● Increase capacity as needed
● Resilience
● Automatic failover and self-healing features
● Flexibility
● Easy to change and provides ability to deploy quick
updates
● Cost Savings
● Deploys efficiently and with less overhead by using
containers and microservices
● Complexity
● Security issues
● Skill required
40
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
41
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Increased Revenue
42
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Envision Phase
▪ Align
▪ Launch
▪ Scale
transporting large volumes of data into and out of the AWS cloud
43
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o The Snow Family was designed for edge computing and data transfer, and it
includes three primary product lines
▪ AWS Snowcone
● Smallest member of the Snow Family, and it is designed to be a
portable, rugged, and secure edge computing and data transfer
device
● Snowcone supports AWS IoT Greengrass and can run edge
computing workloads that use AWS Lambda functions
▪ AWS Snowball
● Larger data transfer device, available in two options
● Snowball Edge Storage Optimized
44
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
45
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Provides fully managed support for file transfers directly into and out of
46
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
47
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
Global Infrastructure
Objective 3.2 - Define the AWS global infrastructure
● AWS Regions
o This infrastructure is organized physically into AWS Regions, and each region is
made up of three or more Availability Zones
o AWS Regions
▪ Physical location in the world where AWS clusters multiple data centers
together
▪ AWS has established Regions all around the world to provide a reliable
▪ These regions allow customers to deploy their applications and data close
to their end-users
o The AWS Cloud contains over 30 geographic regions across the globe, including
over 100 availability zones within those regions
from the other AWS Regions to ensure the greatest possible fault
tolerance and stability
o When choosing the AWS Region to use, you will generally consider several
factors
▪ Latency
48
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● The time it takes for data to travel from one point to another,
typically measured in milliseconds
● The shorter the distance between the customers and the AWS
Region, the lower the latency their systems will experience
▪ Cost
● The cost and pricing for AWS services vary between different
regions
▪ Service Availability
▪ Resiliency
49
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o AWS Regions are used to provide customers with the flexibility to place their
resources and applications close to their end users
● Availability Zones
o Availability Zones (AZs)
one or more data centers equipped with independent power, cooling, and
networking to ensure fault tolerance
▪ AWS spans over 100 AZs across 30-plus geographically dispersed regions
▪ Latency
▪ Cost
▪ Service Availability
50
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Resiliency
● Edge Locations
o Edge Location
▪ Physical site or data center located in major cities and highly populated
areas across the globe that AWS uses to cache and deliver content
▪ AWS Edge Locations are part of the Amazon CloudFront Content Delivery
▪ Fast content delivery network service that securely delivers data, videos,
applications, and APIs to customers globally with low latency and high
transfer speeds
51
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
the users
o AWS Global Accelerator
▪ Networking service that sends the user’s traffic through Amazon Web
▪ When the service is enabled, the user traffic enters AWS's network at the
▪ Caching mechanism helps reduce the load on the origin server, decrease
▪ Increased Scalability
● AWS edge locations handle traffic spikes and distribute the load
across multiple locations
▪ Decreased Costs
52
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Enhanced Security
● Edge Locations are spread across the globe, users from anywhere
can access content quickly and efficiently with consistent and
reliable performance
▪ Customization
53
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Set up the local zone by enabling them in the Virtual Private Cloud
▪ Reduced Latency
▪ Seamless Integration
54
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Cost Savings
▪ Improved Scalability
▪ Flexible Deployment
55
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Machine Learning
▪ Industrial Equipment
▪ Smart Cars
▪ Smart Cities
▪ Virtual Reality
▪ Set them up by creating resources in the Wavelength Zone just like they
▪ The Wavelength Zones are connected to the parent AWS Region through
56
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
same APIs and AWS Management Console they use for AWS Regions
o Once configured, you will find many benefits to using these AWS Wavelength
Zones
▪ Ultra-low Latency
▪ Seamless Integration
▪ Cost Savings
57
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Flexible Deployment
● AWS Outposts
o AWS Outposts
58
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
an AWS Region
o There are numerous benefits to using AWS Outposts
▪ Hybrid Experience
▪ Reduced Latency
59
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
60
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Regions
▪ Edge Locations
▪ Local Zones
▪ Wavelength Zones
61
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
62
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● Takes into account both fixed and variable costs and ongoing costs
associated with maintaining and supporting the project
o Take advantage of
▪ Process Transformation
63
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Business Transformation
64
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Fixed Expenses
● Constant costs
▪ Variable Expenses
▪ CAPEX
▪ OPEX
● Ongoing costs
● Licensing Models
o There are five main licensing models used in cloud computing
o Perpetual Licensing/Lifetime Deal (LTD)
65
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Software licensing model where the customer pays a one-time fee for a
▪ Advantages
▪ Disadvantages
▪ Software licensing model where the customer pays a recurring fee to use
the software
▪ Advantages
▪ Disadvantages
66
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● Costly
o Bring Your Own License (BYOL)
▪ Advantages
▪ Disadvantages
● Compatibility
● No support and maintenance
o Included License
▪ Cost of the software license is included in the price of the cloud service
provided by AWS
management
o License Manager
▪ Advantages
67
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Disadvantages
cloud-based environment
▪ Any instance will use the same hardware and receive the same
68
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
69
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Savings Plans
costs by up to 66%
● EC2 Instance Savings Plans
70
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ The transfer of data into an AWS service from a source that could be
▪ All traffic originating from the Internet that is destined to the AWS Cloud
▪ AWS charges for outgoing data transfer on a tiered basis which means
▪ These cross-availability zone data transfers are charged at the lowest level
▪ Transferring data between two different AWS regions, and this would be a
chargeable event
71
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
"objects", each with a unique identifier, rather than organizing data in file
hierarchies or blocks
● S3 Standard
● Designed for frequently accessed data, offering low latency
and high throughput, but this is also one of the most
expensive storage options
● S3 Intelligent-Tiering
72
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Divides data into fixed-sized blocks and stores them with unique
identifiers, commonly used for database storage and virtual machine file
systems
73
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Organizes and accesses data as a hierarchy of files and folders, much like
▪ The one-zone storage classes are charged at a rate of about half of the
74
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Budget
● Rightsizing
o Rightsizing
75
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Using machine learning algorithms can analyze the usage patterns and
o Ultimately, we use four main strategies when rightsizing our AWS environments
▪ Scaling Down
● Reducing the size of a resource or the number of instances being
used if those resources are consistently being underutilized
▪ Scaling Up
76
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Rightsize the storage resources to better match the actual utilization and
one-time thing
o AWS CloudFormation
● Managed Services
o Managed Services
77
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ AWS's offering where the cloud provider handles the operational tasks of
78
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● AWS Organizations
o AWS Organizations
▪ Powerful tool that allows users to manage and govern multiple AWS
accounts centrally
79
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Receive a single bill for all the accounts in the organization which makes it
▪ When you activate these tags, AWS includes them in the AWS Cost and
multiple accounts
o AWS Organizations tool is a robust tool for managing multiple AWS accounts
across different departments
80
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
value
▪ AWS uses these tags to organize the resource costs on the cost allocation
report
o Chargebacks
▪ In AWS, chargebacks are implemented using the AWS Cost and Usage
Report
o Cost allocation tags can help identify high-cost resources and provide with
insights that can drive cost optimization efforts
81
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
82
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
83
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● The tag key is a unique identifier for the tag, and the tag value is
the data associated with the tag
▪ Cost Categories
▪ Always use consistent tag keys and values across the organization
▪ Always use the AWS Cost Explorer and AWS Cost and Usage Reports
84
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
Connecting to AWS
Objective 3.1 - Define methods of deploying and operating in the AWS Cloud.
● Amazon EC2
● Amazon S3
● Amazon RDS
● Amazon DynamoDB
● AWS Lambda
o The AWS Management Console includes features like Resource Groups and Tag
Editors that allow to organize and manage AWS resources effectively
o The console also provides a Service Health Dashboard that offers real-time
updates on the status of AWS services
o Integrates with the AWS Marketplace
software vendors
85
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o This management console also has increased security features to protect your
account
o The console provides tools for tracking AWS costs and usage
● Programmatic Access
o Programmatic Access
▪ The term programmatic access in AWS refers to the ability to interact with
86
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
87
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ AWS CloudFormation
deployments
88
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Improves collaboration
● Settings customization
● Standardize configuration process
● Versioned, auditable, rolled back (if necessary)
o In AWS, IaC is often implemented using services like
▪ AWS OpsWorks
identical
89
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
disaster recovery
o Infrastructure as Code plays a crucial role in disaster recovery and a key enabler
of Continuous Integration and Continuous Deployment (CI/CD)
90
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
91
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ SSH ensures that all traffic between the local machine and the EC2
instance is encrypted
o Public Internet
services
92
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ The root user has unrestricted access to all AWS services and resources
o Given the root user's extensive access, it is critical that you protect this account
in order to maintain the integrity and security of your AWS resources
▪ Use the AWS CloudTrail tool to monitor and log account activity
architectures
● Least Privilege
93
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ The root user is the only user who has the ability to terminate and close
▪ The root user is also the only user who can create, view, or delete
▪ The root user is the only one who can delete a service-linked role if the
▪ Allows to create and manage AWS users and groups and use permissions
to allow and deny their access to AWS resources and to enforce the
principle of least privilege
o IAM User
94
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ When you create an IAM user, the user is not granted permission to
▪ Always create individual IAM users for each person who needs to use the
o IAM users can be assigned to multiple groups, and each group can contain
multiple users
● Policies
o IAM Policies
95
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Standalone policies that can be attach to multiple users, groups, and roles
▪ Policies that the user create and manage, and that are embedded directly
96
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o IAM policies are a powerful tool for managing access to the organization's AWS
resources
o Authentication
▪ Allows creation and management of AWS users and groups, as well as the
97
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
98
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
AWS resources
o Identity and Access Management provides two functions in terms of cloud
security
99
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
access the AWS Management Console, call AWS APIs, and access
resources
● Access Management
● used to manage users, groups, roles, and policies
● Access Report
● provides insights into who has access to your system
o AWS Identity and Access Management (IAM) is the backbone of security and
access control within the AWS environment
o Through IAM, the user can ensure that the right individuals have the right access
and that the cloud resources remain protected
100
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Okta
▪ Ping Identity
▪ JumpCloud
▪ Google Workspace
o Uses
▪ The IAM Identity Center is also used to grant multi-account access across
▪ The IAM Identity Center paves the way for uninterrupted single sign-on
▪ The IAM Identity Center also grants single sign-on access to Amazon EC2
Windows instances
101
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ The IAM Identity Center speeds up the setup and configuration of single
● Credential Storage
o AWS offers services like the AWS Secrets Manager to ensure secure storage,
access, and management of these sensitive pieces of information
o Credentials
other secrets
▪ The AWS Secrets Manager allows for the rotation of secrets on a schedule
or on demand
102
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ The AWS Secrets Manager tool can also be used to automatically replicate
● Explorer
● Provides key insights and analysis into the operational
health and performance of AWS environment
● OpsCenter
● Provides a central location where operations engineers
and IT professionals can view, investigate, and resolve
operational issues
● Incident Manager
● Enables faster resolution of critical application availability
and performance issues
● Application Manager
● Helps to investigate and remediate issues with resources in
the context of the applications
● AppConfig
103
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
104
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
105
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
Compute Services
Objectives:
● 3.3 – Identify AWS compute services.
● 3.8 - Identify services from other in-scope AWS service categories.
types available
o The AWS Elastic Compute Cloud has a variety of different instance types or
categories
▪ General-purpose Instances
● Designed to provide a balance of compute, memory, and
networking resources
● Under general-purpose instances, you will find various types
under this category
● T2
● T3
● T3a
● T4g
● M5 Instance
106
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
107
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
number of resources
▪ Launch Configuration
108
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Scaling Policies
▪ Health Checks
109
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
seen by subscribers
110
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● Suited for load balancing of HTTP and HTTPS traffic that provides
advanced request routing targeted at the delivery of modern
application architectures, including microservices and containers
● Routes traffic to Amazon VPC
● Operates at Layer 7 (OSI model)
▪ Network Load Balancer
● Used for load balancing of network traffic using TCP, UDP, and TLS
● Suited for high-performance traffic
● Routes traffic to Amazon VPC
● Operates at Layer 4 (OSI model)
▪ Gateway Load Balancer
● Used to deploy, scale, and run third-party virtual networking
appliances
● Customers deploy appliances from the preferred vendor
● Operates at Layers 3 & 4
o Elastic Load Balancing (ELB)
▪ Managed service with the AWS Cloud that allows to focus on delivering
▪ When using the Amazon VPC, the elastic load balancing service can
▪ The Elastic Load Balancing service is used with other AWS services such as
EC2, ECS, EKS, and tools like Amazon CloudFormation and the AWS Billing
111
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ The elastic load balancing service can support a variety of load balancers,
● Containerized Compute
o Containerized Compute
112
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Security
● Each container is isolated from each other
o There are some drawbacks to using containerized compute instead of traditional
virtual machines or EC2 instances
▪ Complexity
● Cluster
● the group of EC2 instances that are used to run the
containers
113
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Once you have created a cluster, you can create a task definition
● Task Definition
● a blueprint for a container
▪ Once you have created a task definition, you can create a service
● Service
● the group of tasks that runs in application
● When you create a service, you specify the task definition that you
want to use, the number of tasks that you want to run, and the
deployment strategy
o Amazon Elastic Kubernetes Service (EKS)
AWS
▪ Kubernetes
● Open-source container orchestration system that allows to deploy,
manage, and scale containerized applications
▪ Advantages
▪ To use EKS
114
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Fully managed Docker image registry that makes it easy to store, manage,
▪ To use ECR
● Once you have created a repository, you can push your Docker
image to the repository
● Use the 'docker push' command to push the Docker image
to the repository
115
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● Once you have pushed your Docker image to ECR, you can use it
with the Elastic Container Service or the Elastic Kubernetes
Service
● Use ECS or the EKS to specify the repository name and the
image tag of the task definition or Kubernetes manifest
o Difference between the Elastic Container Service and the Elastic Kubernetes
Service
● Serverless Compute
o Serverless Compute
116
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Serverless compute can provide us with some great benefits, such as cost
Lamba function
▪ AWS Lambda is suitable for a wide range of applications and use cases
infrastructure
117
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ AWS Fargate is ideal for applications that require isolation at the task
▪ AWS Fargate is ideal for applications that require isolation at the task
● Microservices
● Can be packaged as a container, and each container can be
scaled independently
● Batch Processing
Fargate task
118
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
compute instances
▪ Fully managed service that simplifies the deployment and scaling of web
119
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
compute-intensive
inference jobs
resources on demand
o Amazon AppStream 2.0
120
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ AppStream 2.0 can easily scale any number of users without acquiring,
o Amazon WorkSpaces
▪ Desktop-as-a-Service (DaaS)
121
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ WorkSpaces Web is non-persistent and does not store data after each
session
122
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
Network Services
Objective 3.5: Identify AWS network services.
123
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
having the ability to mix and match products from different vendors
development
▪ The best benefit of an SDN is that it can allow for fully automated
▪ Losing connectivity to the SDN controller could cause the entire network
to go down
attackers to focus on
o 3 Main Types of Software Defined Networks (SDN)
▪ Open SDN
● Open source variant of SDN that relies on open-source technology
like OpenFlow, OpFlex, and OpenStack to operate
▪ Hybrid SDN
● Network that employs traditional SDN protocols to operate itself
▪ SDN Overlay
124
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
where they can launch various AWS resources in a virtual network that
they have defined
125
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Internet Gateways
126
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ VPN Connections
▪ Routers
▪ Firewalls
▪ Switches
o To set up an Amazon VPC, the user must define these components and the
interactions between them
o Amazon Virtual Private Cloud (VPC) is a logically isolated section of the AWS
Cloud where users can launch AWS resources
● VPC Security
o Network Access Control Lists (ACLs)
▪ Each Network ACL is comprised of a numbered list of rules that AWS will
127
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● Inbound Rules
● Control the traffic that’s allowed to enter the subnet
● Outbound Rules
● Govern the traffic that’s allowed to leave the subnet
o Security Groups
▪ Designed to function at the instance level within the Virtual Private Cloud
(VPC)
▪ Each of the Security Groups is comprised of a set of defined rules that will
o It is critically important that the Network ACLs and Security Groups are correctly
configured for security
● DNS
o Domain Name System (DNS)
128
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Second Level
▪ Sub-Domain
▪ Host
● Lowest and most detailed level inside of the DNS hierarchy and
refers to a specific machine
o Uniform Resource Locator (URL)
129
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Types
● A
● AAAA
● CNAME
● MX
● SOA
● PTR
● TXT
● SRV
● NS
o It is common to set up an internal DNS service that lets the cloud instances
within the same network or private cloud access each other
▪ Records created around the domain names that users purchase from a
▪ A setting that tells the DNS resolver how long to cache a query before
130
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o Lookup Types
▪ Recursive Lookup
● DNS server will hunt it down and report back to the user’s resolver
▪ Iterative Lookup
● DNS resolver will continually query DNS servers until it finds the
one with the IP for the domain
● Amazon Route 53
o Amazon Route 53
▪ Scalable and highly available DNS web service that can be used to
▪ Domain Registration
▪ DNS Routing
o Through Route 53, we can configure how different domain names and their
associated DNS records are routed to our infrastructure running within the AWS
Cloud
131
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Amazon S3 Buckets
▪ Container that holds information about how users want to route traffic on
132
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
133
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
WebSocket APIs
o One of the key strengths of API Gateway is its ability to handle all the tasks
involved in accepting and processing a tremendous number of concurrent API
calls
▪ To achieve this, the API gateway must be able to conduct the following
● Traffic Management
● CORS Support
● Authorization and Access Control
● Throttling
● Monitoring
● API Version Management
o API Gateway features
▪ The API Gateway can support RESTful, REST, and WebSocket APIs
● RESTful APIs
● Designed for serverless workloads and HTTP backends that
rely on using HTTP APIs
● REST APIs
134
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ API Gateway allows users to run multiple versions of the same API
simultaneously
▪ Cost savings on a scale because of the tiered pricing model it uses for its
API requests
▪ The API Gateway also offers easy monitoring with performance metrics
▪ API Gateway also offers embedded support for OIDC and OAuth2
▪ Users can execute or code their own Lambda authorizer function from
● Amazon VPN
o Amazon Virtual Private Network (VPN)
135
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
OpenVPN
o There are two types of Amazon Virtual Private Networks commonly used
▪ AWS Client VPN
● Managed client-based VPN service that enables users to securely
access their AWS resources and networks from anywhere
● To use AWS Client VPN
● Setup configurations
● Install client software
● Establish a connection
● Access
▪ AWS Site-to-Site VPN
● Connects users' on-premise networks, remote offices, or branch
offices securely back to their own Amazon VPC
● To use AWS Site-to-Site VPN
● Set up configuration
● Create tunneling
● Access connection
o Benefits
▪ Fully scalable
136
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ AWS Direct Connect service offers a wide range of speeds, starting from
▪ If you are using one of the highest speed connections, such as the 10
137
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ If you are using a slower speed connection, or are using Direct Connect in
138
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
Storage Services
Objective 3.6: Identify AWS storage services.
● Storage Features
o To effectively use cloud-based storage, it is important that you understand the
different storage features
o Compression
service
139
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● Amazon S3
● Deduplication at the object level
● Amazon Elastic Block Store
● Deduplication at the block level
● Amazon Elastic File Storage & Amazon FSx service
● Deduplication at the file level
o Capacity on Demand
● Storage Characteristics
o Cloud Storage
▪ Type of data storage where data is stored on remote servers that can be
140
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Performance
● Characteristic that refers to the speed and reliability of data access
in cloud storage
● A cloud storage provider with high performance will be able to
quickly access and transfer large amounts of data
● High performance storage can also be more expensive
▪ Hot versus Cold Storage
● Hot Storage (Active Storage)
● Characteristic that refers to data that is frequently
accessed and updated
● Hot storage can also be more expensive than cold storage
● Cold Storage (Archival Storage)
● Characteristic that refers to data that is infrequently
accessed and updated
● Data stored in cold storage may take longer to access and
retrieve
o Each cloud service provider uses different names for their different types of hot
and cold storage
141
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o Hot Storage
o Cold Storage
● Object Storage
o Object Storage/Object-based Storage
o Amazon S3
companies
o Objects are stored in S3 buckets and can be organized using shared names
known as 'prefixes'
142
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
to each object
o S3 Batch Operations are also used to simplify the management of your data at
any scale and they allow you to
▪ Amazon S3 offers a range of storage classes designed for specific use cases and
access patterns
● S3 Standard
● Designed for frequently accessed data, offering low latency and
high throughput, and is one of the most expensive storage options
since it is optimized for frequently accessed data
● S3 Standard is ideal for various use cases
▪ Cloud applications
▪ Dynamic websites
143
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Content distribution
144
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● For longer-term storage and for data that does not need to be
accessed quickly or frequently
▪ Cold Storage
145
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Archival data
▪ Retrieval options
▪ Backup
▪ Disaster Recovery
▪ Financial services
▪ Healthcare
▪ Public sector
146
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
147
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ VPC Endpoints
▪ Server-side Encryption
▪ Client-side Encryption
o Microsoft Azure
148
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● Block Storage
o Block Storage
▪ Block storage is great for use-cases that require rapid, consistent Input
▪ High-performance block storage service that was designed for use with
▪ Amazon EBS volumes are placed in a specific Availability Zone where they
▪ EBS also provides options for hard disk drive based storage which can
149
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Amazon Elastic Block Store also provides the ability to save point-in-time
▪ When configuring EC2 instances, it will allow the option of using a general
▪ Amazon EBS also offers seamless encryption of EBS data volumes, boot
▪ Feature of Amazon EBS that ensures that full 16KiB write operations are
▪ Instance stores are perfect for transient data, like buffers, caches, and
150
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● File Storage
o File Storage
▪ Type of cloud storage that is optimized for storing and sharing files
o AWS offers a variety of file system services optimized for different applications
and use cases
o Amazon Elastic File System (EFS)
▪ Serverless, fully elastic file storage system designed to share file data
▪ Amazon EFS supports a wide range of use cases from hosting user's home
▪ Elastic File System provides an NFS-shared file system storage for Linux
151
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ A fully managed file system can be created in seconds using the AWS
Management Console, the AWS Command Line Interface, the AWS API, or
the AWS SDK
99.999 999 999 percent durability rating, which is eleven 9's, and up to
99.99 percent availability rating
● EFS Replication
● Used to replicate the file system data to another AWS
Region or within the same Region in just a few steps
● AWS Backup
● Fully managed backup service that centrally manage and
automate the backup of the Amazon EFS file systems
o Amazon FSx
▪ Amazon FSx is built on the latest AWS compute, networking, and disk
technologies
▪ Amazon FSx can be configured for use with four widely-used file systems
152
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● File Gateway
● Provides a seamless way to connect to the cloud in order
to store application data files and backup images as
durable objects on Amazon S3
● Volume Gateway
● Provides block storage volumes that users can mount as
iSCSI devices from on-premises application servers
153
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● Tape Gateway
● Offers a durable, cost-effective solution to archive users
data in the AWS Cloud
▪ The user can create backup plans to define the backup requirements and
▪ AWS Backup service also allows to set backup retention policies that
automatically retain and expire backups so that the backup storage costs
can be minimized
154
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Helps to minimize downtime and data loss with fast, reliable recovery of
▪ This service can initiate the secure data replication on the source servers
into a staging area subnet in the user AWS account within the AWS
Region selected
▪ Many AWS services, like Amazon RDS and Amazon EC2, support
155
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● The process that involves the production and initial storage of the
data
▪ Access and Use
● Data that is frequently accessed and used for various purposes,
including analysis, processing, or transactional purposes
▪ Archival
● Process that is undertaken when data is no longer frequently
accessed but still needs to be retained for future reference or
compliance purposes
▪ Deletion
● Process that occurs at the end of the data's lifecycle so that the
data can be removed from our systems
o AWS allows users to define lifecycle policies to automate the transition of data
between different storage classes and manage their data's eventual deletion
● Business requirements
● Nature of the data
● Relevance to ongoing business operations
▪ Other considerations
▪ Successive snapshots are incremental and only contain the data that
156
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
include a snapshot for each EBS volume attached to the source instance
▪ Policy type
▪ Resource type
▪ Target tags
▪ Policy schedules
o By effectively managing the data lifecycle in AWS, businesses can optimize costs,
improve operational efficiency, and meet regulatory compliance requirements
● Configuring S3 Buckets
o AWS CloudShell is only available in certain regions
o Amazon Simple Storage Service (S3)
and scalability
157
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
Database Services
Objective 3.4: Identify AWS database services.
● Databases
o Databases
and manipulated
o Structured Databases
▪ Stores data in tables with each table consisting of rows and columns
▪ The columns will contain the data attributes and the rows contains the
158
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o Unstructured Database
variety of data models for accessing and managing data and are designed
to handle data without a predefined schema
require large data volume, low latency, and flexible data models
159
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o In the world of databases, there are two methods for running your databases,
hosted and managed
o Hosted Database
or cloud infrastructure
● Provisioning
● Installation
● Configuration
● Maintaining
● Scaling
● Backup
● Recovery
● Security
o Managed Database
▪ The cloud service provider will take on the responsibility for a range of
administrative tasks
● Hardware Provision
● Software Installation and Updates
● Backups
● Scaling
160
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● Security Measures
● Routine Maintenance
161
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● Amazon RDS
o Amazon Relationship Database Service (RDS)
▪ MySQL
▪ MariaDB
▪ PostgreSQL
162
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Oracle
▪ To do this, you can use the AWS Management Console, the Amazon RDS
▪ Amazon RDS allows for safer, simpler, and faster database updates
▪ Data at rest and in transit are encrypted when using Amazon RDS
163
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● Amazon Aurora
o Amazon Aurora
o Major features
maximum of 128 TB
164
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
40%
● Point-in-time recovery
● User-initiated Database Snapshots in Amazon S3
● Backtrack feature for Aurora MySQL
o Aurora supports migrations from multiple database systems
o Aurora introduces ML and AI functionalities in the database to make real-time
predictions possible through SQL
o When paired with Amazon RDS Proxy, Aurora becomes even more scalable and
resilient to enhance your application performance and security
o Remember, Amazon Aurora is a highly secure, cost-effective, and fully managed
relational database service that provides high performance and scalability
● Amazon DynamoDB
o Amazon DynamoDB
165
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o Main features
● Amazon Neptune
o Amazon Neptune
166
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● Property Graph
● Resource Description Framework (RDF)
▪ Amazon Neptune is known for its high performance level that is achieved
of Redis
o Redis
167
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ One of the main benefits of the Amazon MemoryDB for Redis service is
▪ AWS will handle tasks like patching, backup, and recovery on behalf of the
organization
o To monitor the database, integrate it with AWS CloudWatch
o Amazon MemoryDB for Redis offers the perfect blend of performance, resilience,
scalability, security, and simplicity
168
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
169
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
170
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● Machine Learning
o Machine Learning
▪ To use machine learning, provide it with a labeled data set where you've
▪ As we feed it new data, it can label and categorize that data by itself,
171
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ used to identify objects, faces, text, and other features in images and
172
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
173
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
human language
o In the AWS Cloud, there are two services that provide natural language
capabilities
▪ Amazon Lex
● Conversations come to life by enabling the creation of
sophisticated, natural language chatbots
● Amazon Lex provides the tools needed to
● Builds conversational interfaces
● Comprehends intent
● Integrated with other AWS services
● Fully managed service that helps build conversational interfaces
for applications
▪ Amazon Comprehend
● Service for diving deep into textual content, which can extract
insights that are hidden beneath the surface
● Amazon Comprehend uses machine learning to uncover insights
and relationships within any text provided to the system
● Natural language processing service that helps extract insights
from sets of text-based data
174
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
175
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Search services help businesses sift through vast volumes of data to find
176
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o Inside of AWS, there are four main services that are used for data streaming and
search
▪ Amazon Kinesis
● AWS's flagship data streaming service that allows users to easily
collect, process, and analyze real-time streaming data to derive
insights and respond quickly to new information
▪ Amazon Managed Streaming for Apache Kafka
● Fully managed service that helps users set up, scale, and operate
Apache Kafka clusters in AWS
● Apache Kafka
● Open-source stream-processing software platform that
was originally developed by LinkedIn and then donated to
the Apache Software Foundation
▪ Amazon OpenSearch
● Managed service that makes it easy to deploy, operate, and scale
OpenSearch for log analytics, application monitoring, and other
relevant use case
▪ Amazon Redshift
● Fully managed, petabyte-scale data warehousing service that
offers lightning-fast queries using SQL,
extract-transform-and-load, and Business Intelligence tools
● Redshift is also designed to integrate seamlessly with various data
loading and business intelligence tools
177
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
Security Capabilities
Objective 2.4: Identify components and resources for security.
● Security Groups
o Security Groups
▪ These rules dictate which traffic can enter or leave a particular EC2
instance
● Inbound Rules
● Dictate which incoming traffic is allowed into a given
instance
178
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Set Security Group rules to only allow traffic from specific EC2 instances
▪ Security groups cannot filter traffic based on domain names, it can only
▪ Security groups are essentially a virtual firewall that can be used with EC2
instances
● Network ACLs
o Network Access Control List (ACL)
▪ Offers a layer of security that operates at the sub-net level to grant users
o Within Amazon VPCs, configure network ACL through the creation of inbound
and outbound rules for each of the subnets in the VPC
179
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o Best practices
▪ Always write the network ACL rules from the most specific to the most
broad
and serve as a gatekeeper to manage traffic at the subnet level into or out
of the VPC
● AWS WAF
o AWS Web Application Firewall (AWS WAF)
▪ Security solution that monitors and filters incoming web traffic to protect
monitors the HTTP and HTTPS traffic going to and from a given web
application
o AWS WAF is designed to shield applications against some of the most widespread
web exploits seen on the Internet
CloudWatch
180
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o AWS WAF is a dynamic security solution that scrutinizes HTTP and HTTPS traffic
and allows users to define conditions to block, allow, or monitor web requests
● Encryption Options
o Encryption
181
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● To protect our data in transit, many of the AWS services like AWS
Elastic Load Balancing, Amazon CloudFront, Amazon S3, and
Amazon RDS have built-in capabilities to enable encryption of our
data in transit by default
▪ Data in Processing
● Data currently being used or processed by applications, and
usually being held in systems' RAM or processor caches
● By maintaining a secure environment, regular patching, and
following a principle of least privilege, data remains secure even
during processing
▪ Vital tool that offers guidance to AWS users to optimize their cloud-based
infrastructure
o It is like your own personalized cloud consultant that will continuously
monitoring your AWS resources for you and provide you with recommendations
on the areas that matter most to your organization
▪ Cost Optimization
● This service can identify any idle and underutilized resources and
propose the various ways to reduce costs without compromising
the efficiency of the services
▪ Security
182
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● The service can check for unrestricted ports, weak passwords, and
other potential security threats and then it will offer some
recommendations to improve the security of the cloud
environment
▪ Performance
▪ Fault Tolerance
▪ Service Limits
● The AWS Trusted Advisor can keep an eye on these limits, and
then it can alert anytime the user is getting close to hitting one of
those limits
o The AWS Trusted Advisor is a personalized cloud consultant constantly
monitoring the AWS resources and also helps with fine-tuning those resources
183
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ The AWS Security Blog provides a fresh and continuous stream of the best
security information
o Remember, when navigating the vast world of AWS security, there are three main
sources of information you should consider
● Hosts the best practices and security tools you may need to use
184
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o AWS Marketplace
▪ Curated digital catalog that allows AWS customers to find, test, purchase,
and in processing
o Access Control
185
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
186
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● Compliance in AWS
o Compliance
187
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● Monitoring in AWS
o Monitoring
▪ Allows users to collect and track metrics, set up alarms, and monitor the
▪ CloudWatch can gather logs from the EC2 instances, Lambda functions, or
188
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ CloudWatch has storage and retrieval capabilities so that the user can
look at the data and metrics collected in the past and analyze those
trends and patterns over time
o Monitoring is a process that involves observation, data collection, and analysis
● Auditing in AWS
o Auditing
189
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ AWS Security Hub can also be used with other integrated, third-party
190
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● Detailed findings
● Current status
● Recommendations
▪ AWS Security Hub allows for the integration of third-party services that
● AWS Inspector
o AWS Inspector
▪ This service scrutinizes the running applications hosted by AWS and then
191
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o Use the AWS Inspector service to automatically run scans of the cloud-hosted
applications periodically
o The AWS Inspector is a powerful tool in the AWS security toolkit
● AWS GuardDuty
o AWS GuardDuty
● AWS Shield
o AWS Shield
192
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
193
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
194
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Act as the backbone for companies that want to boost efficiency and
optimize workflows
195
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o AWS offers two reliable solutions to help increase your business' productivity
▪ Amazon Connect
● Designed to replace traditional call center infrastructure with a
cloud-based infrastructure that offers an intuitive, scalable
solution for setting up and managing customer service call centers
● Amazon Connect provides integration capabilities to tailor the
service to provide a personalized experience for each caller or
chat participant
● Manages call volumes and creates chatbots
● Amazon Transcribe
● Amazon Translate
● Amazon Polly
attendant
▪ Amazon Simple Email Service (SES)
● Cloud-based email sending service designed to help digital
marketers and application developers send marketing,
notification, and transactional emails
o Amazon Connect provides us with an all-in-one solution for creating a modern
customer service call center that includes both voice and chat capabilities
196
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o Amazon SES is focused on ensuring that your emails are delivered effectively
while maintaining the integrity and reputation of your domain when sending
those emails
▪ Provide developers the tools and services they need to architect, code,
197
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o AWS has a lot of different developer tools and services to support the entire
software development lifecycle
▪ AWS AppConfig
● Tool that lets developers and IT administrators safely deploy
application configurations in real time
▪ AWS Cloud9
● Integrated Development Environment (IDE) that operates in the
cloud
▪ AWS CloudShell
● Service that grants developers command-line access to AWS
directly from within user's AWS Management Console
▪ AWS CodeArtifact
● Managed artifact repository service that lets teams store, publish,
and share software packages used in their development process
▪ AWS CodeBuild
● Fully managed build service that allows developers to compile,
test, and deploy code without the need to provision or manage
servers
▪ AWS CodeCommit
● Secure, scalable, and managed source control service that can be
used to host private Git repositories
▪ AWS CodeDeploy
● Deployment service that automates application deployments into
various compute services such as EC2 and Lambda
▪ AWS CodePipeline
198
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
199
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ AWS Amplify
● Acts as a bridge between frontend web and mobile developers
and the powerful tools that AWS provides
● At its core, AWS Amplify, is a development platform that provides
a robust set of tools
● CLI
● Authentication Features
● API Access
● Storage Capabilities
● AI/ML
● Amplify provides ready-to-use libraries that can reduce
development time and ensure apps are functional, scalable, and
secure
▪ AWS AppSync
● Managed GraphQL service designed to provide real-time data
▪ AWS Device Farm
● Fully managed testing service that allows developers to test
mobile applications across a vast array of real devices
● With AWS Device Farm, users can test and ensure their
application’s compatibility across numerous devices and across
multiple operating systems
200
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
software, and other technologies that connect and exchange data over
the Internet
o In AWS, there are two main services that you should be aware of when
developing applications that will interact with the Internet of Things
▪ AWS IoT Core
● Managed cloud service that lets connected devices easily and
securely interact with cloud applications and other devices
● AWS IoT Core enables the seamless communication between
devices and the AWS Cloud
▪ AWS IoT Greengrass
● Allows devices to perform local data processing and run AWS
Lambda functions offline
o Remember that the AWS IoT Core ensures your devices are always talking, and
the AWS IoT Greengrass is used to ensure that your devices are never truly
offline
201
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Auto Scaling
● Ensures that applications remain up and running by automatically
adjusting their capacity based on the conditions defined
● Auto scaling can be applied both vertically and horizontally
● Vertical Scaling
● Horizontal Scaling
▪ CloudFormation
● Allows users to define and provision AWS infrastructure resources
using templates written in a JSON or YAML file
● CloudFormation can create massive and complex systems
▪ Compute Optimizer
● Offers recommendations for resources to ensure they are
optimized for performance and cost-effectiveness
▪ Config
● Focused on tracking resource inventory and changes to ensure
compliance and security in a cloud environment
▪ Control Tower
● Designed to automate the setup of a well-architected
multi-account AWS environment
▪ Health Dashboard
● Provides real-time information on the operational status and
performance of AWS services and infrastructure across all regions
202
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Launch Wizard
● Simplifies the deployment of applications on AWS using guided,
best-practice-driven configurations
▪ License Manager
● Streamlines the management and governance of software licenses
across AWS and on-premise environments
▪ Resource Groups
● Allows users to organize AWS resources based on criteria and
operational needs
▪ Tag Editor
● Enables the bulk addition, modification, or deletion of resource
tags across AWS services
▪ Service Catalog
● Allows organizations to create and manage approved catalogs of
resources that are available for use on AWS
203
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
204
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
205
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● AWS Documentation
o AWS Documentation
and tutorials for using the different cloud computing services and
solutions in AWS
o Within AWS, there are three primary types of documentation that you will use
▪ White Papers
● Carefully created documents that are designed to dive deeply into
the technical nature of the various AWS services and architectures
● These white papers are created by AWS experts who ensure that
users are receiving the most accurate, up-to-date, and actionable
insights possible for the different AWS services
● The user can also sometimes find a single white paper for a given
architecture or solution
▪ Blogs
● Go-to source for staying up-to-date with the ever-evolving world
of AWS and its services
● Regularly check the AWS Blogs to gain insights into new features,
tools, or services that might be useful in helping to achieve the
organization's goals
▪ Service Documentation
206
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ The AWS white papers are in-depth technical documents that explore
▪ These white papers are generally more conceptual and strategic in nature
specific task
o AWS Documentation
architectural guidance
207
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
been shared by AWS enthusiasts to help our users navigate the large
ecosystem of AWS services and tools more effectively
o Within the AWS cloud, there are three technical resources that we commonly
utilize
▪ AWS Prescriptive Guidance
● Designed to provide the best practices, recommended
configurations, and in-depth instructions needed for users to best
leverage their AWS services
▪ AWS Knowledge Center
● Vast library filled with articles, white papers, best practices, and
technical documentation that has been created and maintained by
the experts at AWS
▪ AWS re:Post
● Dedicated blogging platform that AWS enthusiasts and AWS
employees can both use to share their insights, updates, and
experiences related to the various AWS services
▪ Helps to ensure that AWS users can receive the help and assistance they
208
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● Cost Optimization
o Cost Optimization
209
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
210
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
from the bad folks who attempt to use AWS services for abusive or illegal
purposes
▪ The AWS Trust and Safety team mission is to detect and prevent misuse
▪ Comprehensive document that delineates the do's and don'ts for users in
the AWS cloud to ensure that AWS remains a secure, efficient, and
user-friendly environment
o The team can ensure that the robustness and integrity of the AWS infrastructure
are safeguarded from most potential threats
o The AWS Trust and Safety team does not operate in a silo, but instead, they
actively collaborate with the customer organization
▪ The Trust and Safety team will look into the matter and provide guidance
on how to ensure that the organization's data remains safe, secure, and
confidential
o The AWS Trust and Safety team is responsible for protecting AWS customers,
partners, and Internet users from threat actors
211
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
212
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Partner Events
● AWS Marketplace
o AWS Marketplace
▪ Serves as a solution hub where the user can find a wide variety of
213
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
● There are vendors who offer their products with many different
pricing models, including a pay-as-you-go model, a
subscription-based model, or simply a free trial-based model
214
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
215
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
Conclusion
● Conclusion
o 4 Domains of AWS Certified Cloud Practitioner
▪ Pearson VUE
216
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ AWS
● You're not allowed to actually carry anything into the exam with
you, but if you're at a local testing center, they will give you a
whiteboard or a dry erase sheet that's about the size of a normal
piece of paper
● Once the clock starts on the exam, you can brain-dump anything
you want onto that paper
● Use the sheet and spend the first 1-2 minutes writing down those
important things you may forget later on
▪ Take a guess
217
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
▪ Be confident
▪ You need to understand why the right answer was right and the wrong
218
https://www.DionTraining.com
AWS Certified Cloud Practitioner
(CLF-C02) (Study Notes)
o Good luck, and I hope to see you again in a future course as you continue
upwards in your cloud computing career and continue to climb up the
certification ladder!
219
https://www.DionTraining.com