AWS CLF-C02 Handbook

The Ultimate Cloud Practitioner Cheat Sheet

Security21

IAM

"Users/Groups/Roles, Permissions, Least Privilege"

Identity & access management

Read More →

IAM Identity Center

"SSO, Single Sign-On, Multi-account access"

Centralized identity management

Read More →

AWS Shield

"DDoS protection, Standard vs Advanced"

DDoS protection

Read More →

AWS WAF

"Firewall, SQL injection, XSS"

Web application firewall

Read More →

AWS KMS

"Encryption keys, Manage encryption"

Key management service

Read More →

CloudHSM

"Hardware Security Module, Dedicated hardware"

Hardware security module

Read More →

GuardDuty

"Threat detection, ML, Crypto attacks"

Intelligent threat detection

Read More →

Inspector

"Security assessment, EC2 vulnerabilities"

Automated security assessment

Read More →

Macie

"Discover sensitive data, PII, S3"

Data privacy service

Read More →

Artifact

"Compliance reports, PCI, ISO, SOC"

Compliance documentation

Read More →

Config

"Record changes, Compliance timeline"

Resource configuration tracking

Read More →

CloudTrail

"Audit API calls, Who did what"

API activity logging

Read More →

Cognito

"Sign-up, Sign-in, User Pools"

Customer identity & access

Read More →

Secrets Manager

"Rotate secrets, DB credentials"

Secrets management

Read More →

Security Hub

"Central dashboard, Compliance, Aggregated alerts"

Unified security posture management

Read More →

Detective

"Investigation, Root cause, Graph"

Investigate security findings

Read More →

Network Firewall

"VPC firewall, Stateful, IPS/IDS"

Managed network firewall for VPCs

Read More →

Firewall Manager

"Central rules, WAF management, Organizations"

Central firewall policy management

Read More →

Certificate Manager (ACM)

"SSL/TLS, Public/Private certs, Auto-renewal"

Provision and manage SSL certificates

Read More →

Directory Service

"Active Directory, AD Connector, SSO"

Managed Microsoft Active Directory

Read More →

AWS STS

"Temporary credentials, AssumeRole, Cross-account"

Targeted temporary access

Read More →

Management18

CloudFormation

"Infrastructure as Code, Templates"

IaC automation

Read More →

OpsWorks

"Managed Chef and Puppet"

Configuration management

Read More →

AWS Auto Scaling

"Scale multiple resources, Predictive scaling"

Unified scaling plans & forecasting

Read More →

Systems Manager

"Patching, Run commands, Parameter Store"

Operational management

Read More →

Trusted Advisor

"Best practices, Cost optimization"

Optimization recommendations

Read More →

Organizations

"Multiple accounts, Consolidated billing"

Account management

Read More →

Control Tower

"Landing Zone, Governance, Multi-account setup"

Multi-account governance

Read More →

Service Catalog

"Self-service, Portfolios, Approved products"

Manage approved IT services

Read More →

Compute Optimizer

"Right-sizing, Recommendations, Machine learning"

Resource optimization

Read More →

CloudWatch

"Metrics, Alarms, Logs, Dashboards"

Monitoring & observability

Read More →

Well-Architected Tool

"Best practices, 6 Pillars, Review"

Architecture reviews

Read More →

Cloud Adoption Framework

"CAF, 6 Perspectives, Business, People, Governance"

Framework for cloud transformation

Read More →

Res. Access Mgr (RAM)

"Share resources, Cross-account, Subnets"

Securely share resources across accounts

Read More →

Health Dashboard

"Personalized status, Maintenance, Service health"

Personalized AWS service health view

Read More →

Managed Services (AMS)

"Ops on behalf, RFC, Patching/Backup"

Infrastructure operations management

Read More →

Marketplace

"Buy software, AMI, SaaS, Third-party"

Digital catalog for software

Read More →

Service Quotas

"Limits, Request increase, Alarms"

Manage service limits

Read More →

EC2 Image Builder

"Golden AMI, Pipeline, Patching"

Automate AMI creation

Read More →